CVE-2022-23722
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.
Date published : 2022-05-02
https://docs.pingidentity.com/bundle/pingfederate-110/page/spk1642790928508.html
https://www.pingidentity.com/en/resources/downloads/pingfederate.html
