VYPR
High severity7.7NVD Advisory· Published Feb 1, 2024· Updated Jun 17, 2026

CVE-2023-36496

CVE-2023-36496

Description

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • cpe:2.3:a:pingidentity:pingdirectory:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:pingidentity:pingdirectory:*:*:*:*:*:*:*:*range: >=8.3.0.0,<=8.3.0.8
    • cpe:2.3:a:pingidentity:pingdirectory:9.2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pingidentity:pingdirectory:9.2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pingidentity:pingdirectory:9.3.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pingidentity:pingdirectory:9.3.0.1:*:*:*:*:*:*:*
    • (no CPE)range: 8.3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.