Brute Force Attack on Private Field Data Leads to Information Disclosure
CVE-2024-23600
2.7LOW
What is CVE-2024-23600?
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.
Affected Version(s)
PingIDM 7.0.0 <= 7.5.0