CVE-2023-36496: Delegated Admin Virtual Attribute Provider Privilege Escalation
Published Feb 1, 2024
·Updated
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.
Affected Software
7 affected components
pingidentity Pingdirectory>=8.3.0.0<=8.3.0.8
pingidentity Pingdirectory>=9.0.0.0<=9.0.0.5
pingidentity Pingdirectory>=9.1.0.0<=9.1.0.2
pingidentity Pingdirectory=9.2.0.0
pingidentity Pingdirectory=9.2.0.1
pingidentity Pingdirectory=9.3.0.0
pingidentity Pingdirectory=9.3.0.1
Event History
Feb 1, 2024
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-36496?
CVE-2023-36496 is categorized as a critical vulnerability due to its potential to allow authenticated users to elevate permissions.
2
How do I fix CVE-2023-36496?
To mitigate CVE-2023-36496, upgrade PingDirectory to a version that is not vulnerable.
3
What products are affected by CVE-2023-36496?
CVE-2023-36496 affects multiple versions of PingDirectory, specifically from 8.3.0.0 to 9.3.0.1.
4
Who can exploit CVE-2023-36496?
CVE-2023-36496 can be exploited by any authenticated user with access to the Directory Server.
5
What are the consequences of exploiting CVE-2023-36496?
Exploiting CVE-2023-36496 allows unauthorized privilege escalation, potentially leading to severe security breaches.