CVE-2025-20059PingAM Java Policy Agent path traversal and parameter injection
What broke
The Ping AM Java Policy Agent accepted a relative path and injected parameters a protected app did not expect. CNA CVSS-B 9.2. February 2025. Ping shipped an agent update.
Why it matters
A policy agent is the enforcement point. Bypass it and every application behind it becomes unauthenticated, regardless of how carefully you configured PingAM. This is the agent-side cousin of OAuth2-Proxy skip_auth_routes.
What to do
- Upgrade every Java Policy Agent. Agents drift. Inventory them, do not assume the last AM upgrade covered them.
- Confirm the agent still fails closed on a malformed path. A 404 is acceptable. A skip is not.
After you patch
Patching closes the entry point. It does not remove access an attacker established through it.
- Revoke sessions and API tokens on the affected system rather than only resetting passwords.
- Audit accounts, tokens, and administrative changes made during the exposure window.
- Rotate credentials the system stored or could reach, including directory service accounts and integration keys. See secrets rotation.
- Treat the system as a pivot: whatever it could authenticate to is in scope until you have checked it.
Sources
- NVD: CVE-2025-20059
- Ping Identity security advisory, February 2025
Related identity CVEs
Related on Start with Identity
- CVECyberArk Conjur path traversal and file disclosure
Conjur allowed a path traversal that disclosed files from the host. CVSS 7.1. Useful in the Cyata chain for reading configuration and secrets material after an
- CVEPingFederate 2025 advisory
A PingFederate CVE from 2025. NVD detail was thin at the time of this brief. Treat it as a PingFederate security update you should already have taken, and confi
- CVESailPoint IdentityIQ directory traversal, CVSS 10.0
IdentityIQ exposed protected static content through improper access control and directory traversal. CVSS 10.0. Disclosed December 2024. e-fixes for 8.2p8, 8.3p
- VendorStyra / Open Policy Agent
strong
- BlogA CVE ID is a name. The value is knowing who the attacker becomes.
We opened a practitioner catalog of identity CVEs: what broke, why IAM teams should care, and what to do this week. Not an NVD mirror. A place to triage SAML wr
- BlogA phishing kit rents an AI voice agent to call theft victims and ask for their 2FA code
SOCRadar documented AnonyMousKIT, a phishing-as-a-service platform built to strip Apple Activation Lock. An AI persona called Alice from Apple Support phones vi