CVE-2022-23722: PingFederate Password Reset via Authentication API Mishandling
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Other sources
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-23722.
What is the severity level of CVE-2022-23722?
The severity level of CVE-2022-23722 is medium.
Which software is affected by CVE-2022-23722?
The Pingidentity Pingfederate software versions 9.3.0 to 9.3.3, 10.0.0 to 10.0.12, 10.1.0 to 10.1.9, 10.2.0 to 10.2.7, 10.3.0 to 10.3.4, and 9.3.3-p15, and 11.0.0 are affected by CVE-2022-23722.
How can an existing user reset another existing user's password using CVE-2022-23722?
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID, or SMS authentication, an existing user can reset another existing user's password.
Where can I find more information about CVE-2022-23722?
You can find more information about CVE-2022-23722 at the following references: [link1](https://docs.pingidentity.com/bundle/pingfederate-110/page/spk1642790928508.html) and [link2](https://www.pingidentity.com/en/resources/downloads/pingfederate.html).