VYPR
Medium severity6.1NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026

CVE-2024-25566

CVE-2024-25566

Description

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks

Affected products

9
  • cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:forgerock:access_management:*:*:*:*:*:*:*:*range: <=7.0.2
    • cpe:2.3:a:forgerock:access_management:7.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:forgerock:access_management:7.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:forgerock:access_management:7.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:forgerock:access_management:7.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:forgerock:access_management:7.5.0:*:*:*:*:*:*:*
  • PingAM/PingAMllm-create
  • Forgerock/PingAMllm-create
  • Ping Identity/PingAMv5
    Range: 7.5.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.