VYPR

Vendor CVEs

Pingidentity

All CVEs

56 total · sorted by risk
  • CVE-2023-34085LowOct 25, 2023
    risk 0.17cvss 2.6epss 0.00

    When an AWS DynamoDB table is used for user attribute storage, it is possible to retrieve the attributes of another user using a maliciously crafted request

  • CVE-2025-21085LowJun 15, 2025
    risk 0.14cvss epss 0.00

    PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.

  • CVE-2024-22477LowJul 9, 2024
    risk 0.12cvss 1.8epss 0.00

    A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.

  • CVE-2025-26862NonOct 27, 2025
    risk 0.00cvss epss 0.00

    Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.

  • CVE-2018-25084LowApr 10, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross…

  • CVE-2014-8489Dec 12, 2014
    risk 0.00cvss epss 0.03

    Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter.

Page 2 of 2