Use of static encryption key material allows forging an authentication token to other users within a tenant organization. MFA may be bypassed by redirecting an authentication flow to a target user. To exploit the vulnerability, must have compromised user credentials.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.pingidentity.com/en/resources/downloads/pingid.html | product vendor advisory |
https://docs.pingidentity.com/bundle/pingid/page/xqz1597139945488.html | vendor advisory |