CVE-2025-20059 is a critical Relative Path Traversal vulnerability in the Ping Identity PingAM Java Policy Agent, affecting versions through 5.10.3, 2023.11.1, and 2024.9. This flaw allows for Parameter Injection, posing a significant risk to the confidentiality and availability of affected systems. With a CVSS score of 9.1 (CRITICAL), it is a network-exploitable vulnerability requiring no user interaction or privileges, indicating a high potential for impact. While there is no known active exploitation, exploit code, or Metasploit/Nuclei modules available, the vulnerability has garnered some community discussion, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Ping Identity | PingAM Java Policy Agent | >= 0, <= 2023.11.1, >= 0, <= 2024.9, >= 0, <= 5.10.3CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.