VYPR
Medium severity5.3NVD Advisory· Published Feb 10, 2022· Updated Jun 17, 2026

CVE-2021-42000

CVE-2021-42000

Description

When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing users password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*range: <=9.3.0
    • cpe:2.3:a:pingidentity:pingfederate:9.3.3:-:*:*:*:*:*:*
    • cpe:2.3:a:pingidentity:pingfederate:9.3.3:p15:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 9.3.3-P15

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.