First published: Thu Feb 01 2024(Updated: )
Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.
Credit: responsible-disclosure@pingidentity.com
Affected Software | Affected Version | How to fix |
---|---|---|
PingDirectory | >=8.3.0.0<=8.3.0.8 | |
PingDirectory | >=9.0.0.0<=9.0.0.5 | |
PingDirectory | >=9.1.0.0<=9.1.0.2 | |
PingDirectory | =9.2.0.0 | |
PingDirectory | =9.2.0.1 | |
PingDirectory | =9.3.0.0 | |
PingDirectory | =9.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36496 is categorized as a critical vulnerability due to its potential to allow authenticated users to elevate permissions.
To mitigate CVE-2023-36496, upgrade PingDirectory to a version that is not vulnerable.
CVE-2023-36496 affects multiple versions of PingDirectory, specifically from 8.3.0.0 to 9.3.0.1.
CVE-2023-36496 can be exploited by any authenticated user with access to the Directory Server.
Exploiting CVE-2023-36496 allows unauthorized privilege escalation, potentially leading to severe security breaches.