PEGA Platform
by Capasystems
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-32090 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2023 | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials | ||
| CVE-2023-50165 | Hig | 0.55 | 8.5 | 0.00 | Jan 31, 2024 | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. | ||
| CVE-2023-28094 | Hig | 0.53 | 8.1 | 0.01 | Jun 22, 2023 | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. | ||
| CVE-2023-50168 | Hig | 0.50 | 7.7 | 0.00 | Mar 14, 2024 | Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. | ||
| CVE-2017-11355 | Med | 0.43 | 6.1 | 0.03 | Aug 2, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to… | ||
| CVE-2023-50166 | Med | 0.40 | 6.1 | 0.00 | Jan 31, 2024 | Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | ||
| CVE-2023-50167 | Med | 0.35 | 5.4 | 0.00 | Mar 6, 2024 | Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. | ||
| CVE-2017-17478 | Med | 0.31 | 4.8 | 0.01 | Feb 27, 2018 | An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context.… | ||
| CVE-2023-32089 | Med | 0.30 | 4.6 | 0.00 | Oct 18, 2023 | Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description | ||
| CVE-2023-32088 | Med | 0.30 | 4.6 | 0.00 | Oct 18, 2023 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation | ||
| CVE-2023-32087 | Med | 0.30 | 4.6 | 0.00 | Oct 18, 2023 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation | ||
| CVE-2023-4843 | Med | 0.28 | 4.3 | 0.00 | Sep 8, 2023 | Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user. |
- risk 0.64cvss 9.8epss 0.01
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
- risk 0.55cvss 8.5epss 0.00
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
- risk 0.53cvss 8.1epss 0.01
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
- risk 0.50cvss 7.7epss 0.00
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
- risk 0.43cvss 6.1epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to…
- risk 0.40cvss 6.1epss 0.00
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
- risk 0.35cvss 5.4epss 0.00
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
- risk 0.31cvss 4.8epss 0.01
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context.…
- risk 0.30cvss 4.6epss 0.00
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
- risk 0.30cvss 4.6epss 0.00
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
- risk 0.30cvss 4.6epss 0.00
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
- risk 0.28cvss 4.3epss 0.00
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.