Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21094 | Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 13 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Input Validation of query search results for private field data in PingIDM OPENIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure. | Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure. |
| Title | PingIDM OpenIDM Query Filter Vulnerability | PingIDM Query Filter Vulnerability |
Wed, 07 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Ping Identity
Published:
Updated: 2024-10-31T19:02:23.103Z
Reserved: 2024-02-29T23:52:30.512Z
Link: CVE-2024-23600
Updated: 2024-10-31T19:02:23.103Z
Status : Awaiting Analysis
Published: 2024-08-01T17:16:09.253
Modified: 2024-11-21T08:57:58.917
Link: CVE-2024-23600
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD