PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.pingidentity.com/en/resources/downloads/pingid.html | vendor advisory |
https://docs.pingidentity.com/bundle/pingid/page/zhy1653552428545.html | vendor advisory |