PT-2024-19957 · Ping Identity · Pingidm

Ksandros Apostoli

+1

·

Published

2024-08-01

·

Updated

2024-11-02

·

CVE-2024-23600

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PingIDM (affected versions not specified)
Description The issue is related to improper input validation of query search results for private field data in the Query Filter module of PingIDM. This allows for a potentially efficient brute forcing approach, leading to information disclosure. The problem can be exploited to guess passwords with less effort than expected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-23600

Affected Products

Pingidm