PT-2025-7534 · Ping Identity · Pingam Java Policy Agent

CVE-2025-20059

·

Published

2025-02-20

·

Updated

2025-03-01

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions PingAM Java Policy Agent versions through 5.10.3 PingAM Java Policy Agent versions through 2023.11.1 PingAM Java Policy Agent versions through 2024.9
Description The issue is a Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent, allowing Parameter Injection. This vulnerability affects PingAM Java Policy Agent versions through 5.10.3, through 2023.11.1, and through 2024.9.
Recommendations For versions through 5.10.3, update to a version later than 5.10.3 to resolve the issue. For versions through 2023.11.1, update to a version later than 2023.11.1 to resolve the issue. For versions through 2024.9, update to a version later than 2024.9 to resolve the issue. As a temporary workaround, consider restricting access to vulnerable parameters to minimize the risk of exploitation.

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14501
CVE-2025-20059

Affected Products

Pingam Java Policy Agent