Pega Infinity
by Capasystems
CVEs (19)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27651 | Cri | 0.68 | 9.8 | 0.54 | Apr 29, 2021 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. | ||
| CVE-2022-24082 | Cri | 0.67 | 9.8 | 0.12 | Jul 19, 2022 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect… | ||
| CVE-2022-24083 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2022 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. | ||
| CVE-2024-10094 | Cri | 0.59 | 9.1 | 0.00 | Nov 20, 2024 | Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code | ||
| CVE-2025-2160 | Hig | 0.53 | 8.1 | 0.00 | Apr 14, 2025 | Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup | ||
| CVE-2021-27654 | Hig | 0.51 | 7.8 | 0.01 | Jan 28, 2022 | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. | ||
| CVE-2025-2161 | Hig | 0.46 | 7.1 | 0.00 | Apr 14, 2025 | Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup | ||
| CVE-2021-27653 | Med | 0.43 | 6.6 | 0.01 | Apr 1, 2021 | Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure. | ||
| CVE-2025-9559 | Med | 0.42 | 6.5 | 0.00 | Oct 16, 2025 | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data. | ||
| CVE-2023-26465 | Med | 0.40 | 6.1 | 0.00 | Jun 9, 2023 | Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. | ||
| CVE-2022-35655 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2022 | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. | ||
| CVE-2022-35654 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2022 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | ||
| CVE-2024-10716 | Med | 0.38 | 5.9 | 0.00 | Dec 5, 2024 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. | ||
| CVE-2025-8681 | Med | 0.36 | 5.5 | 0.00 | Sep 10, 2025 | Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role. | ||
| CVE-2024-6701 | Med | 0.36 | 5.5 | 0.00 | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type. | ||
| CVE-2024-6700 | Med | 0.36 | 5.5 | 0.00 | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name. | ||
| CVE-2024-12211 | Med | 0.35 | 5.4 | 0.00 | Jan 13, 2025 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. | ||
| CVE-2024-6702 | Med | 0.34 | 5.2 | 0.00 | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. | ||
| CVE-2022-35656 | Med | 0.29 | 4.5 | 0.00 | Aug 22, 2022 | Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly. |
- risk 0.68cvss 9.8epss 0.54
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
- risk 0.67cvss 9.8epss 0.12
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect…
- risk 0.64cvss 9.8epss 0.01
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
- risk 0.59cvss 9.1epss 0.00
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
- risk 0.53cvss 8.1epss 0.00
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
- risk 0.51cvss 7.8epss 0.01
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
- risk 0.46cvss 7.1epss 0.00
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
- risk 0.43cvss 6.6epss 0.01
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
- risk 0.42cvss 6.5epss 0.00
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
- risk 0.40cvss 6.1epss 0.00
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
- risk 0.40cvss 6.1epss 0.00
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
- risk 0.40cvss 6.1epss 0.00
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
- risk 0.38cvss 5.9epss 0.00
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
- risk 0.36cvss 5.5epss 0.00
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user with a developer role.
- risk 0.36cvss 5.5epss 0.00
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
- risk 0.36cvss 5.5epss 0.00
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
- risk 0.35cvss 5.4epss 0.00
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
- risk 0.34cvss 5.2epss 0.00
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
- risk 0.29cvss 4.5epss 0.00
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.