VYPR
Low severity3.8NVD Advisory· Published Apr 25, 2023· Updated Jun 17, 2026

CVE-2022-23721

CVE-2022-23721

Description

PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.

Affected products

3
  • cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:*:*:*:*:*:*:*:*range: <2.9
    • (no CPE)range: <2.9
  • Ping Identity/unspecifiedv5
    Range: 2.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.