VYPR

PEGA Platform

by Capasystems

CVEs (12)

  • CVE-2023-32090CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

  • CVE-2023-50165HigJan 31, 2024
    risk 0.55cvss 8.5epss 0.00

    Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

  • CVE-2023-28094HigJun 22, 2023
    risk 0.53cvss 8.1epss 0.01

    Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

  • CVE-2023-50168HigMar 14, 2024
    risk 0.50cvss 7.7epss 0.00

    Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

  • CVE-2017-11355MedAug 2, 2017
    risk 0.43cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to…

  • CVE-2023-50166MedJan 31, 2024
    risk 0.40cvss 6.1epss 0.00

    Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

  • CVE-2023-50167MedMar 6, 2024
    risk 0.35cvss 5.4epss 0.00

    Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

  • CVE-2017-17478MedFeb 27, 2018
    risk 0.31cvss 4.8epss 0.01

    An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context.…

  • CVE-2023-32089MedOct 18, 2023
    risk 0.30cvss 4.6epss 0.00

    Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

  • CVE-2023-32088MedOct 18, 2023
    risk 0.30cvss 4.6epss 0.00

    Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

  • CVE-2023-32087MedOct 18, 2023
    risk 0.30cvss 4.6epss 0.00

    Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation

  • CVE-2023-4843MedSep 8, 2023
    risk 0.28cvss 4.3epss 0.00

    Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.