Pega
Pega Infinity: vulnerabilities and CVEs
Pega Infinity has 10 published vulnerabilities, 0 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months0
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10716 | Medium (4.8) | 0.21% | — | Dec 5, 2024 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. |
| CVE-2024-10094 | Critical (9.8) | 0.48% | — | Nov 20, 2024 | Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code |
| CVE-2024-6702 | Medium (4.8) | 0.26% | — | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. |
| CVE-2024-6701 | Medium (4.8) | 0.26% | — | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type. |
| CVE-2024-6700 | Medium (4.8) | 0.26% | — | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name. |
| CVE-2022-24083 | Critical (9.8) | 0.91% | — | Jul 25, 2022 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. |
| CVE-2022-24082 | Critical (9.8) | 12% | — | Jul 19, 2022 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized… |
| CVE-2021-27654 | High (7.8) | 0.60% | — | Jan 28, 2022 | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. |
| CVE-2021-27651 | Critical (9.8) | 54% | — | Apr 29, 2021 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. |
| CVE-2021-27653 | Medium (4.9) | 1.1% | — | Apr 1, 2021 | Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure. |