pega kayıtları
pega üreticisine ait 50 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-1393 Use of Default Password2
- CWE-425 Direct Request ('Forced Browsing')2
- CWE-285 Improper Authorization2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-295 Improper Certificate Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
50 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2021-27651Kavram kanıtı | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authenticapega · infinity · CWE-287 | Kritik9,8 | — | %53,8 | 29 Nis 2021 |
43Planlayın | CVE-2022-24082Kavram kanıtı | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filterpega · infinity · CWE-502 | Kritik9,8 | — | %12,3 | 19 Tem 2022 |
40Planlayın | CVE-2019-16374İstismar yok | Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length.pega · platform | Kritik9,8 | — | %1,9 | 13 Ağu 2020 |
39İzleyin | CVE-2020-15390İstismar yok | pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfopega · pega platform · CWE-269 | Kritik9,8 | — | %1,3 | 12 Nis 2021 |
39İzleyin | CVE-2022-24083İstismar yok | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.pega · infinity · CWE-285 | Kritik9,8 | — | %0,9 | 25 Tem 2022 |
39İzleyin | CVE-2023-32090İstismar yok | Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials pega · pega platform · CWE-1393 | Kritik9,8 | — | %0,6 | 7 Ağu 2023 |
39İzleyin | CVE-2023-28094İstismar yok | Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credenpega · pega platform · CWE-1393 | Kritik9,8 | — | %0,5 | 22 Haz 2023 |
39İzleyin | CVE-2024-10094İstismar yok | Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Codepega · infinity · CWE-94 | Kritik9,8 | — | %0,5 | 20 Kas 2024 |
35İzleyin | CVE-2020-8775İstismar yok | Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.pega · platform · CWE-79 | Yüksek8,9 | — | %0,8 | 29 Nis 2020 |
35İzleyin | CVE-2020-8773İstismar yok | The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.pega · platform · CWE-79 | Yüksek8,9 | — | %0,8 | 29 Nis 2020 |
35İzleyin | CVE-2020-8774İstismar yok | Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.pega · pega platform · CWE-79 | Yüksek8,8 | — | %0,8 | 29 Nis 2020 |
34İzleyin | CVE-2023-50165İstismar yok | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.pega · platform · CWE-918 | Yüksek8,6 | — | %0,3 | 31 Oca 2024 |
32İzleyin | CVE-2019-16387İstismar yok | PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request pega · pega platform · CWE-668 | Yüksek8,1 | — | %1,0 | 26 Kas 2019 |
31İzleyin | CVE-2021-27654İstismar yok | Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.pega · infinity · CWE-640 | Yüksek7,8 | — | %0,6 | 28 Oca 2022 |
31İzleyin | CVE-2023-26466İstismar yok | A user with non-Admin access can change a configuration file on the client to modify the Server URL.pega · synchronization engine · CWE-285 | Yüksek7,8 | — | %0,2 | 10 Nis 2023 |
30İzleyin | CVE-2023-50168İstismar yok | Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.pega · pega platform · CWE-611 | Yüksek7,7 | — | %0,4 | 14 Mar 2024 |
27İzleyin | CVE-2017-11356Kavram kanıtı | The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privilpega · pega platform · CWE-200 | Orta6,5 | — | %3,5 | 2 Ağu 2017 |
26İzleyin | CVE-2023-28093İstismar yok | A user with a compromised configuration can start an unsigned binary as a service.pega · synchronization engine · CWE-295 | Orta6,5 | — | %1,4 | 10 Nis 2023 |
26İzleyin | CVE-2025-9559İstismar yok | Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to pega · pega platform · CWE-639 | Orta6,5 | — | %0,4 | 16 Eki 2025 |
25İzleyin | CVE-2017-11355Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web scripega · pega platform · CWE-79 | Orta6,1 | — | %2,9 | 2 Ağu 2017 |
24İzleyin | CVE-2020-23957İstismar yok | Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-Tpega · pega platform · CWE-79 | Orta6,1 | — | %0,7 | 15 Ara 2020 |
24İzleyin | CVE-2020-24353İstismar yok | Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.pega · pega platform · CWE-79 | Orta6,1 | — | %0,6 | 9 Kas 2020 |
24İzleyin | CVE-2022-35654İstismar yok | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.pega · pega platform · CWE-79 | Orta6,1 | — | %0,5 | 22 Ağu 2022 |
24İzleyin | CVE-2022-35655İstismar yok | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.pega · pega platform · CWE-79 | Orta6,1 | — | %0,5 | 22 Ağu 2022 |
24İzleyin | CVE-2023-26465İstismar yok | Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.pega · pega platform · CWE-79 | Orta6,1 | — | %0,4 | 9 Haz 2023 |
- CVE-2021-2765155Planlayın
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentica
KritikCVSS 9,8Kavram kanıtıEPSS %54pega · infinity29 Nis 2021
- CVE-2022-2408243Planlayın
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filter
KritikCVSS 9,8Kavram kanıtıEPSS %12pega · infinity19 Tem 2022
- CVE-2019-1637440Planlayın
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length.
KritikCVSS 9,8İstismar yokEPSS %2pega · platform13 Ağu 2020
- CVE-2020-1539039İzleyin
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo
KritikCVSS 9,8İstismar yokEPSS %1pega · pega platform12 Nis 2021
- CVE-2022-2408339İzleyin
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
KritikCVSS 9,8İstismar yokEPSS %1pega · infinity25 Tem 2022
- CVE-2023-3209039İzleyin
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
KritikCVSS 9,8İstismar yokEPSS %1pega · pega platform7 Ağu 2023
- CVE-2023-2809439İzleyin
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default creden
KritikCVSS 9,8İstismar yokEPSS %1pega · pega platform22 Haz 2023
- CVE-2024-1009439İzleyin
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
KritikCVSS 9,8İstismar yokEPSS %0pega · infinity20 Kas 2024
- CVE-2020-877535İzleyin
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
YüksekCVSS 8,9İstismar yokEPSS %1pega · platform29 Nis 2020
- CVE-2020-877335İzleyin
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
YüksekCVSS 8,9İstismar yokEPSS %1pega · platform29 Nis 2020
- CVE-2020-877435İzleyin
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
YüksekCVSS 8,8İstismar yokEPSS %1pega · pega platform29 Nis 2020
- CVE-2023-5016534İzleyin
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
YüksekCVSS 8,6İstismar yokEPSS %0pega · platform31 Oca 2024
- CVE-2019-1638732İzleyin
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request
YüksekCVSS 8,1İstismar yokEPSS %1pega · pega platform26 Kas 2019
- CVE-2021-2765431İzleyin
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
YüksekCVSS 7,8İstismar yokEPSS %1pega · infinity28 Oca 2022
- CVE-2023-2646631İzleyin
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
YüksekCVSS 7,8İstismar yokEPSS %0pega · synchronization engine10 Nis 2023
- CVE-2023-5016830İzleyin
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
YüksekCVSS 7,7İstismar yokEPSS %0pega · pega platform14 Mar 2024
- CVE-2017-1135627İzleyin
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privil
OrtaCVSS 6,5Kavram kanıtıEPSS %4pega · pega platform2 Ağu 2017
- CVE-2023-2809326İzleyin
A user with a compromised configuration can start an unsigned binary as a service.
OrtaCVSS 6,5İstismar yokEPSS %1pega · synchronization engine10 Nis 2023
- CVE-2025-955926İzleyin
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to
OrtaCVSS 6,5İstismar yokEPSS %0pega · pega platform16 Eki 2025
- CVE-2017-1135525İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web scri
OrtaCVSS 6,1Kavram kanıtıEPSS %3pega · pega platform2 Ağu 2017
- CVE-2020-2395724İzleyin
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-T
OrtaCVSS 6,1İstismar yokEPSS %1pega · pega platform15 Ara 2020
- CVE-2020-2435324İzleyin
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
OrtaCVSS 6,1İstismar yokEPSS %1pega · pega platform9 Kas 2020
- CVE-2022-3565424İzleyin
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
OrtaCVSS 6,1İstismar yokEPSS %1pega · pega platform22 Ağu 2022
- CVE-2022-3565524İzleyin
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
OrtaCVSS 6,1İstismar yokEPSS %0pega · pega platform22 Ağu 2022
- CVE-2023-2646524İzleyin
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
OrtaCVSS 6,1İstismar yokEPSS %0pega · pega platform9 Haz 2023