Relative Path Traversal Vulnerability in Ping Identity PingAM Java Policy Agent
CVE-2025-20059
9.2CRITICAL
What is CVE-2025-20059?
The Ping Identity PingAM Java Policy Agent is susceptible to a Relative Path Traversal vulnerability that can allow for unauthorized Parameter Injection. This security concern impacts various versions of the agent, specifically those before version 5.10.3, and also affects 2023.11.1 and 2024.9. Exploitation of this vulnerability may enable attackers to manipulate input parameters, potentially gaining access to protected resources or executing harmful actions within the application.
Affected Version(s)
PingAM Java Policy Agent 0 <= 5.10.3
PingAM Java Policy Agent 0 <= 5.10.3
PingAM Java Policy Agent 0 <= 2023.11.1