Product
pega infinity
18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-10716
CVE-2024-10094
CVE-2024-6702
CVE-2024-6701
CVE-2024-6700
CVE-2022-24083
CVE-2022-24082
CVE-2021-27654
CVE-2021-42555
CVE-2021-35969
CVE-2021-33499
CVE-2021-33498
CVE-2021-32545
CVE-2021-27651
CVE-2021-27653
CVE-2018-5386
CVE-2018-5385
CVE-2018-5384
>= 8.1 and <= 8.8.5
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
>= 6.0 and < 8.1.9
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
>= 8.1 and < 24.1.3
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
>= 8.1 and < 24.1.3
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
>= 8.1 and < 24.1.3
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
>= 7.3.1 and <= 8.7.2
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
>= 8.1.0 and < 8.7.3
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and p
>= 8.2.1 and <= 8.6.1
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
>= 25.0 and < 26.2
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
>= 22.0 and < 26
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
< 26
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
< 26
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
< 26
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
>= 8.2.1 and <= 8.5.2
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local
>= 7.4.0 and < 8.5.3
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
<= 2.2
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an infor
< 2.2
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to byp
< 2.2
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If succe