CVE-2022-23725

HIGH

Pingidentity Pingid Integration For W... - Insufficiently Protected Credentials

Title source: rule

Description

PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.

Scores

CVSS v3 7.7
EPSS 0.0003
EPSS Percentile 9.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Classification

CWE
CWE-522 CWE-288 CWE-732
Status published

Affected Products (1)

pingidentity/pingid_integration_for_windows_login < 2.8

Timeline

Published Jun 30, 2022
Tracked Since Feb 18, 2026