cbcvebase.

Pegasystems Pega Platform vulnerabilities

10 known vulnerabilities affecting pegasystems/pega_platform.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2023-28094P3CRITICALCVSS 9.8≥ 7.4, < unspecified≥ unspecified, < 8.8.*2023-06-22
CVE-2023-28094 [CRITICAL] CWE-1393 CVE-2023-28094: Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prio Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
nvd
CVE-2023-32090P3CRITICALCVSS 9.8≥ 6.1, ≤ 7.3.12023-08-07
CVE-2023-32090 [CRITICAL] CWE-1393 CVE-2023-32090: Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
nvd
CVE-2023-50165P3HIGHCVSS 8.6≥ 8.2.1, ≤ 23.1.02024-01-31
CVE-2023-50165 [HIGH] CWE-918 CVE-2023-50165: Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could ex Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
nvd
CVE-2023-50168P3HIGHCVSS 7.7≥ 6.x, < 8.8.52024-03-14
CVE-2023-50168 [HIGH] CWE-611 CVE-2023-50168: Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
nvd
CVE-2023-50166P4MEDIUMCVSS 6.1≥ 8.5.4, ≤ 8.8.32024-01-31
CVE-2023-50166 [MEDIUM] CWE-79 CVE-2023-50166: Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the r Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
nvd
CVE-2023-50167P4MEDIUMCVSS 6.1≥ 7.1.7, < 23.1.22024-03-06
CVE-2023-50167 [MEDIUM] CWE-79 CVE-2023-50167: Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html cont Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
nvd
CVE-2023-32089P4MEDIUMCVSS 6.1≥ 8.1, < 8.8.32023-10-18
CVE-2023-32089 [MEDIUM] CWE-79 CVE-2023-32089: Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
nvd
CVE-2023-32088P4MEDIUMCVSS 6.1≥ 8.1, < 23.1.12023-10-18
CVE-2023-32088 [MEDIUM] CWE-79 CVE-2023-32088: Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creatio Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
nvd
CVE-2023-32087P4MEDIUMCVSS 6.1≥ 8.1, < 23.1.12023-10-18
CVE-2023-32087 [MEDIUM] CWE-79 CVE-2023-32087: Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
nvd
CVE-2023-4843P4MEDIUMCVSS 4.8≥ 7.1, < 8.8.42023-09-08
CVE-2023-4843 [MEDIUM] CWE-74 CVE-2023-4843: Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utiliz Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
nvd
Pegasystems Pega Platform vulnerabilities | cvebase