Page 3 of 12 results (0.002 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management. La API de autenticación en Ping Identity PingFederate versiones anteriores a 10.3, maneja inapropiadamente determinados aspectos de la administración de contraseñas externas • https://docs.pingidentity.com/bundle/pingfederate-103/page/cou1615333347158.html •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter. Vulnerabilidad de redirección abierta en startSSO.ping en SP Endpoints en Ping Identity PingFederate 6.10.1 permite a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a través de una URL en el parámetro TargetResource. PingFederate 6.10.1 SP Endpoints suffers from an insecure open redirection vulnerability. • http://packetstormsecurity.com/files/129454/PingFederate-6.10.1-SP-Endpoints-Open-Redirect.html http://seclists.org/fulldisclosure/2014/Dec/35 http://tetraph.com/security/cves/cve-2014-8489-ping-identity-corporation-pingfederate-6-10-1-sp-endpoints-dest-redirect-privilege-escalation-security-vulnerability •