Pegasystems Pega Platform vulnerabilities
10 known vulnerabilities affecting pegasystems/pega_platform.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2023-28094P3CRITICALCVSS 9.8≥ 7.4, < unspecified≥ unspecified, < 8.8.*2023-06-22
CVE-2023-28094 [CRITICAL] CWE-1393 CVE-2023-28094: Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prio
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
nvd
CVE-2023-32090P3CRITICALCVSS 9.8≥ 6.1, ≤ 7.3.12023-08-07
CVE-2023-32090 [CRITICAL] CWE-1393 CVE-2023-32090: Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
Pega platform clients who are using versions 6.1 through 7.3.1 may be
utilizing default credentials
nvd
CVE-2023-50165P3HIGHCVSS 8.6≥ 8.2.1, ≤ 23.1.02024-01-31
CVE-2023-50165 [HIGH] CWE-918 CVE-2023-50165: Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could ex
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
nvd
CVE-2023-50168P3HIGHCVSS 7.7≥ 6.x, < 8.8.52024-03-14
CVE-2023-50168 [HIGH] CWE-611 CVE-2023-50168: Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
nvd
CVE-2023-50166P4MEDIUMCVSS 6.1≥ 8.5.4, ≤ 8.8.32024-01-31
CVE-2023-50166 [MEDIUM] CWE-79 CVE-2023-50166: Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the r
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
nvd
CVE-2023-50167P4MEDIUMCVSS 6.1≥ 7.1.7, < 23.1.22024-03-06
CVE-2023-50167 [MEDIUM] CWE-79 CVE-2023-50167: Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html cont
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
nvd
CVE-2023-32089P4MEDIUMCVSS 6.1≥ 8.1, < 8.8.32023-10-18
CVE-2023-32089 [MEDIUM] CWE-79 CVE-2023-32089: Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
nvd
CVE-2023-32088P4MEDIUMCVSS 6.1≥ 8.1, < 23.1.12023-10-18
CVE-2023-32088 [MEDIUM] CWE-79 CVE-2023-32088: Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creatio
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
nvd
CVE-2023-32087P4MEDIUMCVSS 6.1≥ 8.1, < 23.1.12023-10-18
CVE-2023-32087 [MEDIUM] CWE-79 CVE-2023-32087: Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
nvd
CVE-2023-4843P4MEDIUMCVSS 4.8≥ 7.1, < 8.8.42023-09-08
CVE-2023-4843 [MEDIUM] CWE-74 CVE-2023-4843: Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utiliz
Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.
nvd