Ping Identity PingAM Java Policy Agent Relative Path Traversal Vulnerability Allowing Parameter Injection
Vulnerability
A relative path traversal vulnerability has been identified in the Ping Identity PingAM Java Policy Agent. This vulnerability, which allows parameter injection, affects versions through 5.10.3, through 2023.11.1, and through 2024.9. The issue could also be present in older, unsupported versions.
Impact
Exploitation of this vulnerability could lead to unauthorized access to protected resources by bypassing policy enforcement.
Remediation
Users are advised to upgrade to PingAM Java Agent versions 2024.11, 2023.11.2, or 5.10.4. For PingAM Java Agent version 2024.9, an additional mitigation step is to add a specific property assignment to the AgentBootstrap.properties file, which will cause the agent to reject incoming URLs with certain path characteristics.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
