PT-2025-7534 · Ping Identity · Pingam Java Policy Agent
CVE-2025-20059
·
Publicado
2025-02-20
·
Atualizado
2025-03-01
CVSS v3.1
9.4
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PingAM Java Policy Agent versions through 5.10.3
PingAM Java Policy Agent versions through 2023.11.1
PingAM Java Policy Agent versions through 2024.9
Description
The issue is a Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent, allowing Parameter Injection. This vulnerability affects PingAM Java Policy Agent versions through 5.10.3, through 2023.11.1, and through 2024.9.
Recommendations
For versions through 5.10.3, update to a version later than 5.10.3 to resolve the issue.
For versions through 2023.11.1, update to a version later than 2023.11.1 to resolve the issue.
For versions through 2024.9, update to a version later than 2024.9 to resolve the issue.
As a temporary workaround, consider restricting access to vulnerable parameters to minimize the risk of exploitation.
Correção
Relative Path Traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pingam Java Policy Agent