CVE-2024-10094

EUVD-2024-33391
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
PegaCNA
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
pegainfinity
6.0 ≤
𝑥
< 8.1.9
pegainfinity
8.2 ≤
𝑥
< 8.2.8
pegainfinity
8.3.0 ≤
𝑥
< 8.3.6
pegainfinity
8.4.0 ≤
𝑥
< 8.4.6
pegainfinity
8.5 ≤
𝑥
< 8.5.6
pegainfinity
8.6.0 ≤
𝑥
< 8.6.6
pegainfinity
8.7.0 ≤
𝑥
≤ 8.8.5
pegainfinity
23.1.0 ≤
𝑥
< 23.1.4
pegainfinity
24.1.0 ≤
𝑥
< 24.1.2
𝑥
= Vulnerable software versions