PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
References
Link | Resource |
---|---|
https://docs.pingidentity.com/bundle/pingid/page/zhy1653552428545.html | Vendor Advisory |
https://www.pingidentity.com/en/resources/downloads/pingid.html | Vendor Advisory |
Configurations
Information
Published : 2022-06-30 13:15
Updated : 2022-07-12 09:31
NVD link : CVE-2022-23725
Mitre link : CVE-2022-23725
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
pingidentity
- pingid_integration_for_windows_login