Vulnerability Details CVE-2022-23721
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.6%
CVSS Severity
CVSS v3 Score 3.8
Products affected by CVE-2022-23721
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:-
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:1.0
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:1.2
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:1.3
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.0
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.1
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.2
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.3
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.3.1
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.4.2
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.7
-
cpe:2.3:a:pingidentity:pingid_integration_for_windows_login:2.8