本ページは pega platform に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2023-50166 | Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | [email protected] | 6.1 | 0.12% | 2024-01-31 | 2024-11-21 |
| CVE-2023-50165 | Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. | [email protected] | 8.5 | 0.09% | 2024-01-31 | 2024-11-21 |
| CVE-2023-32089 | Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description | [email protected] | 4.6 | 0.11% | 2023-10-18 | 2024-11-21 |
| CVE-2023-32088 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation | [email protected] | 4.6 | 0.11% | 2023-10-18 | 2024-11-21 |
| CVE-2023-32087 | Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation | [email protected] | 4.6 | 0.11% | 2023-10-18 | 2024-11-21 |
| CVE-2019-16374 | Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control. | [email protected] | 9.8 | 1.17% | 2020-08-13 | 2024-11-21 |
| CVE-2020-8775 | Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags. | [email protected] | 8.9 | 0.53% | 2020-04-29 | 2024-11-21 |
| CVE-2020-8773 | The Richtext Editor in Pega Platform before 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability. | [email protected] | 8.9 | 0.53% | 2020-04-29 | 2024-11-21 |