Relative Path Traversal Vulnerability in Ping Identity PingAM Java Policy Agent
CVE-2025-20059

9.2CRITICAL

Key Information:

Vendor
CVE Published:
20 February 2025

What is CVE-2025-20059?

The Ping Identity PingAM Java Policy Agent is susceptible to a Relative Path Traversal vulnerability that can allow for unauthorized Parameter Injection. This security concern impacts various versions of the agent, specifically those before version 5.10.3, and also affects 2023.11.1 and 2024.9. Exploitation of this vulnerability may enable attackers to manipulate input parameters, potentially gaining access to protected resources or executing harmful actions within the application.

Affected Version(s)

PingAM Java Policy Agent 0 <= 5.10.3

PingAM Java Policy Agent 0 <= 5.10.3

PingAM Java Policy Agent 0 <= 2023.11.1

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.