Vulnerabilities (CVE)

Filtered by vendor Pega Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-27654 1 Pega 1 Infinity 2022-02-03 4.6 MEDIUM 7.8 HIGH
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
CVE-2020-8773 1 Pega 1 Platform 2020-04-30 6.0 MEDIUM 8.9 HIGH
The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability.
CVE-2020-8775 1 Pega 1 Platform 2020-04-30 6.0 MEDIUM 8.9 HIGH
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
CVE-2020-8774 1 Pega 1 Pega Platform 2020-04-30 6.8 MEDIUM 8.8 HIGH
Pega Platform before version 8.2.6 is affected by a Reflected Cross-Site Scripting vulnerability in the "ActionStringID" function.
CVE-2019-16387 1 Pega 1 Pega Platform 2019-12-19 5.5 MEDIUM 8.1 HIGH
** DISPUTED ** PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_ListDatabases request while using a low-privilege account. (This can perform actions and retrieve data that only an administrator should have access to.) NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect.