Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown

CVE-2020-23957

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSettings.pzStartTracerSession request to a PRAuth URI.
Attacker Value
Unknown

CVE-2020-24353

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
Attacker Value
Unknown

CVE-2019-16374

Disclosure Date: August 13, 2020 (last updated February 21, 2025)
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.
Attacker Value
Unknown

CVE-2020-8775

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
Attacker Value
Unknown

CVE-2020-8774

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
Attacker Value
Unknown

CVE-2020-8773

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2019-16387

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Attacker Value
Unknown

CVE-2019-16386

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Attacker Value
Unknown

CVE-2011-4967

Disclosure Date: November 19, 2019 (last updated November 27, 2024)
tog-Pegasus has a package hash collision DoS vulnerability
Attacker Value
Unknown

CVE-2019-16388

Disclosure Date: January 23, 2019 (last updated November 08, 2023)
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect