VYPR

PingIDM

by Pingidentity

CVEs (3)

  • CVE-2020-10654CriMay 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.

  • CVE-2025-20628MedApr 7, 2026
    risk 0.45cvss epss 0.00

    An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode. This means attackers can spoof a…

  • CVE-2022-23724MedMay 4, 2022
    risk 0.42cvss 6.4epss 0.00

    Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.