Ping Identity PingIDM versions 7.0.0 through 7.5.0 enabled an attacker with read access to the User collection, to abuse API query filters in order to obtain managed and/or internal user's passwords in either plaintext or encrypted variants, based on configuration. The API clearly prevents the password in either plaintext or encrypted to be...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2391918
💾 Ping Identity PingIDM 7.5.0 Query Filter Injection
⏱️ vor 635d 14h (01.11.2024 um 16:11 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com