CVE-2022-23720 Details
Description
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by PingFederate, into PingID Windows Login user endpoints. Using sensitive full permissions properties file outside of a privileged trust boundary leads to an increased risk of exposure or discovery, and an attacker could leverage these credentials to perform administrative actions against PingID APIs or endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.pingidentity.com/bundle/pingid/page/zhy1653552428545.html | CVE | Release NotesVendor Advisory |
| https://www.pingidentity.com/en/resources/downloads/pingid.html | CVE | ProductVendor Advisory |
| https://docs.pingidentity.com/bundle/pingid/page/zhy1653552428545.html | [email protected] | Release NotesVendor Advisory |
| https://www.pingidentity.com/en/resources/downloads/pingid.html | [email protected] | ProductVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
| CWE-648 | Incorrect Use of Privileged APIs | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pingidentity pingid integration for windows login | < 2.8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 13, 2022 | Initial Analysis | [email protected] |