Platform
by Pega
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16374 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2020 | Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control. | ||
| CVE-2020-8775 | Hig | 0.58 | 8.9 | 0.01 | Apr 29, 2020 | Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags. | ||
| CVE-2020-8773 | Hig | 0.58 | 8.9 | 0.01 | Apr 29, 2020 | The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability. | ||
| CVE-2023-50165 | Hig | 0.55 | 8.5 | 0.00 | Jan 31, 2024 | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. | ||
| CVE-2023-50166 | Med | 0.40 | 6.1 | 0.00 | Jan 31, 2024 | Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | ||
| CVE-2023-32089 | Med | 0.30 | 4.6 | 0.00 | Oct 18, 2023 | Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description | ||
| CVE-2023-32088 | Med | 0.30 | 4.6 | 0.00 | Oct 18, 2023 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation | ||
| CVE-2023-32087 | Med | 0.30 | 4.6 | 0.00 | Oct 18, 2023 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation |
- risk 0.64cvss 9.8epss 0.02
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.
- risk 0.58cvss 8.9epss 0.01
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
- risk 0.58cvss 8.9epss 0.01
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
- risk 0.55cvss 8.5epss 0.00
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
- risk 0.40cvss 6.1epss 0.00
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
- risk 0.30cvss 4.6epss 0.00
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
- risk 0.30cvss 4.6epss 0.00
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
- risk 0.30cvss 4.6epss 0.00
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation