Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Miguel García Martín

Researcher fromSEC Consult Vulnerability Lab
#53159of 53,635
2.7Total CVSS
Vulnerabilities · 1
PT-2024-19957
2.7
2024-08-01
Ping Identity · Pingidm · CVE-2024-23600
**Name of the Vulnerable Software and Affected Versions** PingIDM (affected versions not specified) **Description** The issue is related to improper input validation of query search results for private field data in the Query Filter module of PingIDM. This allows for a potentially efficient brute forcing approach, leading to information disclosure. The problem can be exploited to guess passwords with less effort than expected. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.