CVE-2024-23600: Ping Identity Pingidm
Low severity, CVSS 2.7. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.
Affected products
- Ping Identity Pingidm: from 7.0.0, up to and including 7.5.0
Published 2024-08-01. Last modified 2026-06-17.