CVE-2025-62181
Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only applies to deprecated basic-authentication feature and other more secure authentication mechanisms are recommended. A fix is being provided in the 24.1.4, 24.2.4, and 25.1.1 patch releases. Please note: Basic credentials authentication service type is deprecated started in 24.2 version: https://docs.pega.com/bundle/platform/page/platform/release-notes/security/whats-new-security-242.html.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.44%
- Percentil entre todas las CVEs puntuadas: 36
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-204
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-62181",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-62181",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-12-11T15:25:30.998804Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@pega.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@pega.com",
"affectedData": [
{
"vendor": "Pegasystems",
"product": "Pega Infinity",
"versions": [
{
"status": "affected",
"version": "7.1.0",
"lessThan": "Infinity 25.1.1",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-12-10T21:16:04.303",
"references": [
{
"url": "https://support.pega.com/support-doc/pega-security-advisory-j25-vulnerability-remediation-note",
"source": "security@pega.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security@pega.com",
"description": [
{
"lang": "en",
"value": "CWE-204"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user authentication process, where a difference in response time could allow a remote unauthenticated user to determine if a username is valid or not. This only applies to deprecated basic-authentication feature and other more secure authentication mechanisms are recommended. A fix is being provided in the 24.1.4, 24.2.4, and 25.1.1 patch releases. Please note: Basic credentials authentication service type is deprecated started in 24.2 version: https://docs.pega.com/bundle/platform/page/platform/release-notes/security/whats-new-security-242.html."
},
{
"lang": "es",
"value": "Las versiones de Pega Platform 7.1.0 hasta Infinity 25.1.0 están afectadas por una Enumeración de Usuarios. Este problema ocurre durante el proceso de autenticación de usuario, donde una diferencia en el tiempo de respuesta podría permitir a un usuario remoto no autenticado determinar si un nombre de usuario es válido o no. Esto solo aplica a la característica de autenticación básica obsoleta y se recomiendan otros mecanismos de autenticación más seguros. Se está proporcionando una solución en las versiones de parche 24.1.4, 24.2.4 y 25.1.1. Tenga en cuenta: El tipo de servicio de autenticación de credenciales básicas está obsoleto a partir de la versión 24.2: https://docs.pega.com/bundle/platform/page/platform/release-notes/security/whats-new-security-242.html."
}
],
"lastModified": "2026-09-28T22:10:00.160",
"sourceIdentifier": "security@pega.com"
}