Authentication API Vulnerability in PingFederate by Ping Identity
CVE-2021-40329
9.8CRITICAL
What is CVE-2021-40329?
The Authentication API in Ping Identity's PingFederate, prior to version 10.3, is susceptible to vulnerabilities due to improper management of external password processes. This oversight could potentially allow unauthorized access or manipulation of user credentials, increasing the risk of security breaches within affected systems.
Affected Version(s)
PingFederate 9.2.3
PingFederate 9.3.3
PingFederate 10.0.9