Vulnerabilities
CVE-2024-12211
MEDIUMPega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
CVE-2024-10716
MEDIUMPega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
CVE-2024-10094
CRITICALPega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
CVE-2024-6702
MEDIUMPega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
CVE-2024-6701
MEDIUMPega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
CVE-2024-6700
MEDIUMPega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
CVE-2023-50168
HIGHPega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
CVE-2023-50167
MEDIUMPega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
CVE-2023-50166
MEDIUMPega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2023-50165
HIGHPega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
CVE-2023-32089
MEDIUMPega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
CVE-2023-32088
MEDIUMPega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
CVE-2023-32087
MEDIUMPega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
CVE-2023-4843
MEDIUMPega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
CVE-2023-32090
CRITICALPega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
CVE-2023-28094
HIGHPega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
CVE-2023-26465
HIGHPega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
CVE-2023-26466
HIGHA user with non-Admin access can change a configuration file on the client to modify the Server URL.
CVE-2023-28093
HIGHA user with a compromised configuration can start an unsigned binary as a service.
CVE-2023-26467
HIGHA man in the middle can redirect traffic to a malicious server in a compromised configuration.
CVE-2022-35656
MEDIUMPega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
CVE-2022-35655
MEDIUMPega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
CVE-2022-35654
MEDIUMPega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2022-24083
CRITICALPassword authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
CVE-2022-24082
CRITICALIf an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.
CVE-2021-27654
HIGHForgotten password reset functionality for local accounts can be used to bypass local authentication checks.
CVE-2021-27651
CRITICALIn versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.