VYPR
Medium severity6.5NVD Advisory· Published May 2, 2022· Updated Jun 17, 2026

CVE-2022-23722

CVE-2022-23722

Description

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:pingidentity:pingfederate:*:*:*:*:*:*:*:*range: >=9.3.0,<9.3.3
    • cpe:2.3:a:pingidentity:pingfederate:11.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pingidentity:pingfederate:9.3.3:p15:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 11.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.