Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Ping Identity/
  3. Ping Authorization

Ping Authorization

AuthorizationAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 13 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~46 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Policy-based granular access control.

by Ping Identity · pingidentity.com · source ↗

Known CVEs (13)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-20746 ↗2026

    Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attribu…

  • CVE-2025-20059 ↗CRITICAL 9.12025

    Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.…

  • CVE-2024-23316 ↗2024

    HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to send specially crafted http header requests to create a request smuggling conditi…

  • CVE-2018-25084 ↗LOW 3.52023

    A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java…

  • CVE-2022-23718 ↗HIGH 7.62022

    PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise…

  • CVE-2021-41770 ↗HIGH 7.52021

    Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

  • CVE-2021-40329 ↗CRITICAL 9.82021

    The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

  • CVE-2021-31923 ↗MEDIUM 5.32021

    Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.

  • CVE-2021-39270 ↗HIGH 7.52021

    In Ping Identity RSA SecurID Integration Kit before 3.2, user impersonation can occur.

  • CVE-2020-10654 ↗CRITICAL 9.82020

    Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating…

  • CVE-2019-13564 ↗MEDIUM 6.12019

    XSS exists in Ping Identity Agentless Integration Kit before 1.5.

  • CVE-2017-6059 ↗HIGH 7.52017

    Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to spoof page content via a malicious URL provided to…

  • CVE-2014-8489 ↗MEDIUM 6.42014

    Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via …

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Identity & Access Management products

see all →
  • 1Password Extended Access Management · 1Password
  • AD Guardian Cloud · CionSystems
  • ARCON Privileged Access Management · ARCON
  • Abbey Labs · Abbey Labs
  • Aceiss · Aceiss
  • Active Directory Permissions Analyzer · Paramount Defenses
  • Adaptive MFA · Okta
  • Adaxes · softerra adaxes