CVE-2024-10094

Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
PegaCNA
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
pegainfinity
6.0 ≤
𝑥
< 8.1.9
pegainfinity
8.2 ≤
𝑥
< 8.2.8
pegainfinity
8.3.0 ≤
𝑥
< 8.3.6
pegainfinity
8.4.0 ≤
𝑥
< 8.4.6
pegainfinity
8.5 ≤
𝑥
< 8.5.6
pegainfinity
8.6.0 ≤
𝑥
< 8.6.6
pegainfinity
8.7.0 ≤
𝑥
≤ 8.8.5
pegainfinity
23.1.0 ≤
𝑥
< 23.1.4
pegainfinity
24.1.0 ≤
𝑥
< 24.1.2
𝑥
= Vulnerable software versions