Showing 10 vulnerabilities on this page for Pega Platform

Signals CISA KEV Ransomware Nuclei
Pegasystems vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

CWE-611Mar 14, 2024
CVSS7.7v3.1EPSS0.392%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

CWE-79Mar 6, 2024
CVSS5.4v3.1EPSS0.298%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.

CWE-79Jan 31, 2024
CVSS6.1v3.1EPSS0.336%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

CWE-918Jan 31, 2024
CVSS8.5v3.1EPSS0.338%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description

CWE-79Oct 18, 2023
CVSS4.6v3.1EPSS0.298%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

CWE-79Oct 18, 2023
CVSS4.6v3.1EPSS0.298%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation

CWE-79Oct 18, 2023
CVSS4.6v3.1EPSS0.298%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega Platform versions 7.1 to 8.8.3 are affected by an HTML Injection issue with a name field utilized in Visual Business Director, however this field can only be modified by an authenticated administrative user.

CWE-74CWE-79Sep 8, 2023
CVSS4.3v3.1EPSS0.295%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

CWE-1393CWE-287Aug 7, 2023
CVSS9.8v3.1EPSS0.621%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

CWE-1393Jun 22, 2023
CVSS8.1v3.1EPSS0.53%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX