CVE-2022-23722

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Configurations

Configuration 1

cpe:2.3:a:pingidentity:pingfederate:9.3.3:p15:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingfederate:11.0.0:*:*:*:*:*:*:*

Information

Published : 2022-05-02 10:15

Updated : 2022-05-10 02:24


NVD link : CVE-2022-23722

Mitre link : CVE-2022-23722

Products Affected
No products.
CWE