Home/Product/pega infinity
Product

pega infinity

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-10716
>= 8.1 and <= 8.8.5
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
5.9MEDIUM
CVE-2024-10094
>= 6.0 and < 8.1.9
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
9.1CRITICAL
CVE-2024-6702
>= 8.1 and < 24.1.3
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
5.2MEDIUM
CVE-2024-6701
>= 8.1 and < 24.1.3
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.
5.5MEDIUM
CVE-2024-6700
>= 8.1 and < 24.1.3
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.
5.5MEDIUM
CVE-2022-24083
>= 7.3.1 and <= 8.7.2
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
9.8CRITICAL
CVE-2022-24082
>= 8.1.0 and < 8.7.3
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and p
9.8CRITICAL
CVE-2021-27654
>= 8.2.1 and <= 8.6.1
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
7.8HIGH
CVE-2021-42555
>= 25.0 and < 26.2
Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
7.5HIGH
CVE-2021-35969
>= 22.0 and < 26
Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.
7.5HIGH
CVE-2021-33499
< 26
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
7.5HIGH
CVE-2021-33498
< 26
Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).
7.5HIGH
CVE-2021-32545
< 26
Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.
7.5HIGH
CVE-2021-27651
>= 8.2.1 and <= 8.5.2
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local
9.8CRITICAL
CVE-2021-27653
>= 7.4.0 and < 8.5.3
Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.
6.6MEDIUM
CVE-2018-5386
<= 2.2
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an infor
7.5HIGH
CVE-2018-5385
< 2.2
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to byp
8.8HIGH
CVE-2018-5384
< 2.2
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If succe
9.8CRITICAL
threatengine.sh