Vulnerability Description
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://backstage.forgerock.com/docs/idcloud/latest/release-notes/regular-channe
- https://backstage.forgerock.com/knowledge/kb/article/a95212747
- http://seclists.org/fulldisclosure/2024/Oct/18
FAQ
What is CVE-2024-23600?
CVE-2024-23600 is a vulnerability with a CVSS score of 2.7 (LOW). Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.
How severe is CVE-2024-23600?
CVE-2024-23600 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-23600?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.