CVE-2022-23722
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Tim
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
MEDIUM · CVSS 6.5
EPSS 0.00131
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0