« Volver al listado

CVE-2022-23726

Estado: ModificadaMedia (4.9)—

PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-23726",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-23726",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-20T16:01:58.211864Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsible-disclosure@pingidentity.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "responsible-disclosure@pingidentity.com",
      "affectedData": [
        {
          "vendor": "Ping Identity",
          "product": "PingCentral",
          "versions": [
            {
              "status": "affected",
              "version": "1.10",
              "lessThan": "1.10",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.9",
              "lessThan": "1.9.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.8",
              "lessThan": "1.8.4",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "java"
          ]
        }
      ]
    }
  ],
  "published": "2022-09-30T15:15:09.360",
  "references": [
    {
      "url": "https://docs.pingidentity.com/bundle/pingcentral-110/page/sdd1651696160285.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://www.pingidentity.com/en/resources/downloads/pingcentral.html",
      "tags": [
        "Product"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://docs.pingidentity.com/bundle/pingcentral-110/page/sdd1651696160285.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.pingidentity.com/en/resources/downloads/pingcentral.html",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsible-disclosure@pingidentity.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information."
    },
    {
      "lang": "es",
      "value": "PingCentral versiones anteriores a las enumeradas exponen endpoints de actuadores de Spring Boot que, con autenticación administrativa, devuelven grandes cantidades de información confidencial del entorno y de la aplicación"
    }
  ],
  "lastModified": "2026-06-17T04:30:42.667",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pingidentity:pingcentral:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C23023AB-7445-41E0-8C3D-C4200C806D56",
              "versionEndExcluding": "1.8.4",
              "versionStartIncluding": "1.8"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingcentral:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9790D2A1-7E0E-40A5-A05E-03E9E15C548C",
              "versionEndExcluding": "1.9.3",
              "versionStartIncluding": "1.9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsible-disclosure@pingidentity.com"
}