CVE-2022-23722

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/05/2022
Last modified:
07/11/2023

Description

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:* 9.3.0 (including) 9.3.3 (excluding)
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.12 (excluding)
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:* 10.1.0 (including) 10.1.9 (excluding)
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:* 10.2.0 (including) 10.2.7 (excluding)
cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:* 10.3.0 (including) 10.3.4 (excluding)
cpe:2.3:a:pingidentity:pingfederate:9.3.3:p15:*:*:*:*:*:*
cpe:2.3:a:pingidentity:pingfederate:11.0.0:*:*:*:*:*:*:*