Pega
Pega Infinity: vulnerabilidades y CVE
Pega Infinity tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-10716 | Media (4.8) | 0.21% | — | 5 dic 2024 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. |
| CVE-2024-10094 | Crítica (9.8) | 0.48% | — | 20 nov 2024 | Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code |
| CVE-2024-6702 | Media (4.8) | 0.26% | — | 12 sept 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. |
| CVE-2024-6701 | Media (4.8) | 0.26% | — | 12 sept 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type. |
| CVE-2024-6700 | Media (4.8) | 0.26% | — | 12 sept 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name. |
| CVE-2022-24083 | Crítica (9.8) | 0.91% | — | 25 jul 2022 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. |
| CVE-2022-24082 | Crítica (9.8) | 12% | — | 19 jul 2022 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized… |
| CVE-2021-27654 | Alta (7.8) | 0.60% | — | 28 ene 2022 | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. |
| CVE-2021-27651 | Crítica (9.8) | 54% | — | 29 abr 2021 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. |
| CVE-2021-27653 | Media (4.9) | 1.1% | — | 1 abr 2021 | Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure. |