Impact
The vulnerability is a role‑based access control flaw in PingFederate’s administrative expression evaluation endpoint. It permits users with certain administrative roles to invoke the expression evaluation feature beyond the permissions that are intended for those roles.
Affected Systems
Ping Identity PingFederate deployments that utilize the administrative expression evaluation endpoint. No specific product version is listed, so any installation that provides this functionality may be affected.
Risk and Exploitability
The CVSS score of 8.5 classifies the flaw as high severity. The EPSS score is reported as less than 1%, indicating a very low probability of exploitation. It is not listed in the CISA KEV catalog. The most likely attack vector involves an internal user who possesses an administrative role that should not have access to the expression evaluation endpoint.
OpenCVE Enrichment