CyberRota Analysis
AI-GeneratedAn improper validation vulnerability in PingAM allows attackers to manipulate ID Token claims through crafted requests, potentially bypassing authentication controls. This could lead to privilege escalation or impersonation of users in certain configurations. Organizations using PingAM should prioritize addressing this critical vulnerability to protect against unauthorized access and potential data breaches.
Original NVD Description
An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to privilege escalation or impersonation.