CVE-2023-39219: Admin Console Denial of Service via Java class enumeration
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39219?
CVE-2023-39219 is a vulnerability in PingFederate Administrative Console that allows the console to become unresponsive with crafted Java class loading enumeration requests.
Which software versions are affected by CVE-2023-39219?
The PingFederate software versions affected by CVE-2023-39219 are 10.3.0 to 10.3.12, 11.1.0 to 11.1.7, 11.2.0 to 11.2.6, and 11.3.
What is the severity of CVE-2023-39219?
CVE-2023-39219 has a severity rating of high, with a CVSS score of 7.5.
How can I fix CVE-2023-39219?
To fix CVE-2023-39219, you should update your PingFederate software to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-39219?
You can find more information about CVE-2023-39219 in the PingFederate documentation and downloads page.