Ping Identity PingAM Java Policy Agent Relative Path Traversal Vulnerability Allowing Parameter Injection

Vulnerability

A relative path traversal vulnerability has been identified in the Ping Identity PingAM Java Policy Agent. This vulnerability, which allows parameter injection, affects versions through 5.10.3, through 2023.11.1, and through 2024.9. The issue could also be present in older, unsupported versions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to protected resources by bypassing policy enforcement.

Remediation

Users are advised to upgrade to PingAM Java Agent versions 2024.11, 2023.11.2, or 5.10.4. For PingAM Java Agent version 2024.9, an additional mitigation step is to add a specific property assignment to the AgentBootstrap.properties file, which will cause the agent to reject incoming URLs with certain path characteristics.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.