CVE-2025-20059: PingAM Java Policy Agent path traversal
Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20059?
CVE-2025-20059 is rated as a high-severity vulnerability due to its potential for parameter injection via relative path traversal.
How do I fix CVE-2025-20059?
To fix CVE-2025-20059, update the Ping Identity PingAM Java Policy Agent to the latest version that addresses this vulnerability.
What versions are affected by CVE-2025-20059?
CVE-2025-20059 affects versions of Ping Identity PingAM Java Policy Agent up to and including 5.10.3, 2023.11.1, and 2024.9.
What type of vulnerability is CVE-2025-20059?
CVE-2025-20059 is classified as a relative path traversal vulnerability.
Can CVE-2025-20059 lead to unauthorized access?
Yes, CVE-2025-20059 can potentially lead to unauthorized access due to the parameter injection flaw.