CVE-2023-39219: Pingidentity Pingfederate

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests

Affected products

  • Pingidentity Pingfederate: from 10.3.0, up to and including 10.3.12; from 11.1.0, up to and including 11.1.7; from 11.2.0, up to and including 11.2.6; version 11.3.0 only

Published 2023-10-25. Last modified 2026-06-17.