Show filters
57 Total Results
Displaying 21-30 of 57
Sort by:
Attacker Value
Unknown
CVE-2022-35656
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings directly.
0
Attacker Value
Unknown
CVE-2022-35655
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
0
Attacker Value
Unknown
CVE-2022-35654
Disclosure Date: August 22, 2022 (last updated February 24, 2025)
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
0
Attacker Value
Unknown
CVE-2022-24083
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
0
Attacker Value
Unknown
CVE-2022-24082
Disclosure Date: July 19, 2022 (last updated February 24, 2025)
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.
0
Attacker Value
Unknown
CVE-2021-27654
Disclosure Date: January 28, 2022 (last updated February 23, 2025)
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
0
Attacker Value
Unknown
CVE-2021-43561
Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An XSS issue was discovered in the google_for_jobs (aka Google for Jobs) extension before 1.5.1 and 2.x before 2.1.1 for TYPO3. The extension fails to properly encode user input for output in HTML context. A TYPO3 backend user account is required to exploit the vulnerability.
0
Attacker Value
Unknown
CVE-2021-27651
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
0
Attacker Value
Unknown
CVE-2020-15390
Disclosure Date: April 12, 2021 (last updated February 22, 2025)
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
0
Attacker Value
Unknown
CVE-2021-27653
Disclosure Date: March 30, 2021 (last updated February 22, 2025)
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
0