CVE-2022-23726
mediumCVSS v3 Base Score
5.4
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Characteristics
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
High
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: September 30, 2022 (1321 days ago)
Last Modified: November 21, 2024
Vendor: ForgeRock
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.