« Volver al listado

CVE-2023-36496

Estado: ModificadaAlta (8.8)—

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-36496",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-36496",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-02T18:01:23.224460Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsible-disclosure@pingidentity.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 5.3,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "responsible-disclosure@pingidentity.com",
      "affectedData": [
        {
          "vendor": "Ping Identity",
          "product": "PingDirectory",
          "versions": [
            {
              "status": "affected",
              "version": "8.3",
              "versionType": "8.3.0.9",
              "lessThanOrEqual": "8.3.0.8"
            },
            {
              "status": "affected",
              "version": "9.0",
              "versionType": "9.0.0.6",
              "lessThanOrEqual": "9.0.0.5"
            },
            {
              "status": "affected",
              "version": "9.1",
              "versionType": "9.1.0.3",
              "lessThanOrEqual": "9.1.0.2"
            },
            {
              "status": "affected",
              "version": "9.2",
              "versionType": "9.2.0.2",
              "lessThanOrEqual": "9.2.0.1"
            },
            {
              "status": "affected",
              "version": "9.3",
              "lessThan": "9.3.0.1",
              "versionType": "9.3.0.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-01T23:15:09.107",
  "references": [
    {
      "url": "https://docs.pingidentity.com/r/en-us/pingdirectory-93/ynf1693338390284",
      "tags": [
        "Release Notes"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://support.pingidentity.com/s/article/SECADV039",
      "tags": [
        "Permissions Required"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://www.pingidentity.com/en/resources/downloads/pingdirectory-downloads.html",
      "tags": [
        "Product"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://docs.pingidentity.com/r/en-us/pingdirectory-93/ynf1693338390284",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.pingidentity.com/s/article/SECADV039",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.pingidentity.com/en/resources/downloads/pingdirectory-downloads.html",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsible-disclosure@pingidentity.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.\n"
    },
    {
      "lang": "es",
      "value": "El complemento del proveedor de atributos virtuales Delegated Admin Privilege, cuando está habilitado, permite a un usuario autenticado elevar sus permisos en Directory Server."
    }
  ],
  "lastModified": "2026-06-17T06:06:24.123",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pingidentity:pingdirectory:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2962B5D8-A12A-4D50-99AE-6355AB08F5DC",
              "versionEndIncluding": "8.3.0.8",
              "versionStartIncluding": "8.3.0.0"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingdirectory:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70836EEB-D037-4560-962B-630C9CCD1262",
              "versionEndIncluding": "9.0.0.5",
              "versionStartIncluding": "9.0.0.0"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingdirectory:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBC21BB8-89C1-4DEA-A6D4-F44B99CEEB66",
              "versionEndIncluding": "9.1.0.2",
              "versionStartIncluding": "9.1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingdirectory:9.2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "402022A7-8257-4453-A488-3B87767FFC2E"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingdirectory:9.2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20441BBB-9D6F-4AB5-A007-087AEAE5B7C0"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingdirectory:9.3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66F04A80-B97A-4C03-B75B-F44CEAB7BE15"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingdirectory:9.3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE606D4B-6F7A-4334-BB4E-8D161E3E9C35"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsible-disclosure@pingidentity.com"
}