Skip to main content

Vendor/product archive

pega / infinity CVEs

Beta · best-effort

10 CVEs tagged to pega / infinity4 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2024-10716

Published Dec 5, 2024

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10094

Published Nov 20, 2024

Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6702

Published Sep 12, 2024

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6701

Published Sep 12, 2024

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6700

Published Sep 12, 2024

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24083

Published Jul 25, 2022

Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24082

Published Jul 19, 2022

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27654

Published Jan 28, 2022

Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27651

Published Apr 29, 2021

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-27653

Published Apr 1, 2021

Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1