CVE-2022-23725: PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances
Published Jun 30, 2022
·Updated
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
Affected Software
1 affected component
pingidentity Pingid Integration For Windows Login<2.8
Event History
Jun 30, 2022
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-23725?
CVE-2022-23725 is a vulnerability in PingID Windows Login prior to version 2.8 that does not properly set permissions on the Windows Registry entries used to store sensitive API keys.
2
What is the severity of CVE-2022-23725?
CVE-2022-23725 has a severity rating of high (5.5).
3
How does CVE-2022-23725 affect PingID Windows Login?
CVE-2022-23725 affects PingID Windows Login versions prior to 2.8 by not properly setting permissions on Windows Registry entries.
4
How can I fix CVE-2022-23725?
To fix CVE-2022-23725, update PingID Windows Login to version 2.8 or higher.
5
Where can I find more information about CVE-2022-23725?
More information about CVE-2022-23725 can be found in the PingID documentation and downloads page.