CVE-2025-20059

Published Feb 20, 2025

Last updated 10 months ago

Overview

Description
Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.9.
Source
responsible-disclosure@pingidentity.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Severity
CRITICAL

Weaknesses

responsible-disclosure@pingidentity.com
CWE-23
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-23

Social media

Hype score
Not currently trending
  1. CVE-2025-20059 impacts Ping Identity #CVE-2025-20059 #PingIdentity https://t.co/IZIg5lHwad

    @pravin_karthik

    1 Mar 2025

    26 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ⚠️ Vulnerability Alert: PingAM Java Agent Relative Path Traversal Vulnerability 📅 Timeline: Disclosure: 2025-02-15, Patch Release: 2025-02-20 📌 Attribution: Ping Identity 🆔 CVE ID: CVE-2025-20059 📊 Base Score: 9.2 📏 CVSS Metrics:… https://t.co/XygmVXexk8

    @syedaquib77

    28 Feb 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🚨 Enhanced Security Advisory: PingAM Java Agent Vulnerability (CVE-2025-20059) 🚨 🔴 Critical Severity: CVSS 9.2 | Affects All Supported Versions 📜 Advisory Overview: A critical security vulnerability (CVE-2025-20059) has been identified in PingAM Java Agent, allowing for… http

    @syedaquib77

    21 Feb 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-20059 ⚠️🔴 CRITICAL (9.1) 🏢 Ping Identity - PingAM Java Policy Agent 🏗️ 0 🔗 https://t.co/ieKegxDMfC #CyberCron #VulnAlert https://t.co/SO9DQO6yim

    @cybercronai

    20 Feb 2025

    135 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  5. [CVE-2025-20059: CRITICAL] Ping Identity's PingAM Java Policy Agent is vulnerable to Relative Path Traversal and Parameter Injection, impacting versions up to 2024.9.Cybersecurity flaw!#cybersecurity,#vulnerability https://t.co/7oEjz9dl0e https://t.co/llPjMsfraO

    @CveFindCom

    20 Feb 2025

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-20059 Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3… https://t.co/1mpwdykAyk

    @CVEnew

    20 Feb 2025

    285 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.