CVE-2022-23725
HIGHPingidentity Pingid Integration For W... - Insufficiently Protected Credentials
Title source: ruleDescription
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
Scores
CVSS v3
7.7
EPSS
0.0003
EPSS Percentile
9.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Classification
CWE
CWE-522
CWE-288
CWE-732
Status
published
Affected Products (1)
pingidentity/pingid_integration_for_windows_login
< 2.8
Timeline
Published
Jun 30, 2022
Tracked Since
Feb 18, 2026