← Voltar à pesquisa de CVEs

CVE-2026-20746

PingDirectory

Descrição

Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.

CVSS 6.3EPSS 0.27799999999999997%Risco 0.65
Ver fonte
Publicação
2026-06-12 04:17:04
Versões afetadas
unknown
Tipo
Software crítico
Vetor
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:X/RE:M/U:Amber