When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-28658 When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Ping Identity

Published:

Updated: 2024-08-03T03:51:46.174Z

Reserved: 2022-01-19T00:00:00

Link: CVE-2022-23722

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-02T22:15:09.647

Modified: 2024-11-21T06:49:10.940

Link: CVE-2022-23722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.