logo

PingAM Java Agent Vulnerability Allows Attackers to Bypass Security

ID: 50e7a4eb-da0c-5c05-a1e9-b78784630111

STIX ID: report--50e7a4eb-da0c-5c05-a1e9-b78784630111

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

A critical Relative Path Traversal vulnerability (CVE-2025-20059) has been disclosed in Ping Identity's PingAM Java Agent (affecting multiple 2023–2024 and earlier versions), which may allow attackers to bypass policy enforcement by manipulating semicolons in URL paths; Ping Identity provides a temporary AgentBootstrap.properties regex workaround and urges upgrades to patched releases while CISA is expected to add the CVE to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.