CVE-2025-20059: Ping Identity Pingam Java Policy Agent

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.9.

Affected products

  • Ping Identity Pingam Java Policy Agent: up to and including 5.10.3; up to and including 2023.11.1; up to and including 2024.9

Published 2025-02-20. Last modified 2026-06-17.