CVE-2022-23726 MEDIUM

CVE-2022-23726

Vendor Ping Identity
Product PingCentral
Weakness CWE-200 · Info exposure
Published September 30, 2022
Last update May 20, 2025

CVSS base score

5.4/10
Attack vector Adjacent
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authentication return large amounts of sensitive environmental and application information.

Key dates

02Disclosure timeline

September 30, 2022 CVE published
May 20, 2025 Record updated