Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown

CVE-2020-23957

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
Attacker Value
Unknown

CVE-2020-24353

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
Attacker Value
Unknown

CVE-2020-8774

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Attacker Value
Unknown

CVE-2019-16387

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Attacker Value
Unknown

CVE-2019-16386

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Attacker Value
Unknown

CVE-2019-16388

Disclosure Date: January 23, 2019 (last updated November 08, 2023)
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Attacker Value
Unknown

CVE-2017-17478

Disclosure Date: February 27, 2018 (last updated November 26, 2024)
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 characters) into a text field in Designer Studio, after establishing context. Designer Studio is the developer workbench for Pega Platform. That XSS payload will execute when other developers visit the affected pages.
0
Attacker Value
Unknown

CVE-2017-11356

Disclosure Date: August 02, 2017 (last updated November 26, 2024)
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.
0
Attacker Value
Unknown

CVE-2017-11355

Disclosure Date: August 02, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to the System database schema modification page.
0