PT-2025-7534 · Ping Identity · Pingam Java Policy Agent

Published

2025-02-20

·

Updated

2025-03-01

·

CVE-2025-20059

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions PingAM Java Policy Agent versions through 5.10.3 PingAM Java Policy Agent versions through 2023.11.1 PingAM Java Policy Agent versions through 2024.9
Description The issue is a Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent, allowing Parameter Injection. This vulnerability affects PingAM Java Policy Agent versions through 5.10.3, through 2023.11.1, and through 2024.9.
Recommendations For versions through 5.10.3, update to a version later than 5.10.3 to resolve the issue. For versions through 2023.11.1, update to a version later than 2023.11.1 to resolve the issue. For versions through 2024.9, update to a version later than 2024.9 to resolve the issue. As a temporary workaround, consider restricting access to vulnerable parameters to minimize the risk of exploitation.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

BDU:2025-14501
CVE-2025-20059

Affected Products

Pingam Java Policy Agent