๐Ÿ” CVE Alert

CVE-2023-28094

HIGH 8.1
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.

CWE CWE-1393
Vendor pegasystems
Product pega platform
Published Jun 22, 2023
Last Updated Dec 6, 2024
Stay Ahead of the Next One

Get instant alerts for pegasystems pega platform

Be the first to know when new high vulnerabilities affecting pegasystems pega platform are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Pegasystems / Pega Platform
7.4 < unspecified unspecified < 8.8.*

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.pega.com: https://support.pega.com/support-doc/pega-security-advisory-%E2%80%93-c23-vulnerability-default-operators?

Credits

Mohamad Shokor