CVE-2022-23726

MEDIUM

Pingidentity Pingcentral < 1.8.4 - Information Disclosure

Title source: rule
STIX 2.1

Description

PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0021
EPSS Percentile 43.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-732
Status published
Products (1)
pingidentity/pingcentral 1.8 - 1.8.4
Published Sep 30, 2022
Tracked Since Feb 18, 2026