Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-16374

Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2019-16374
  • Pega » Platform » Version: 8.1.0
    cpe:2.3:a:pega:platform:8.1.0
  • Pega » Platform » Version: 8.1.1
    cpe:2.3:a:pega:platform:8.1.1
  • Pega » Platform » Version: 8.1.2
    cpe:2.3:a:pega:platform:8.1.2
  • Pega » Platform » Version: 8.1.3
    cpe:2.3:a:pega:platform:8.1.3
  • Pega » Platform » Version: 8.1.4
    cpe:2.3:a:pega:platform:8.1.4
  • Pega » Platform » Version: 8.1.5
    cpe:2.3:a:pega:platform:8.1.5
  • Pega » Platform » Version: 8.1.6
    cpe:2.3:a:pega:platform:8.1.6
  • Pega » Platform » Version: 8.1.7
    cpe:2.3:a:pega:platform:8.1.7
  • Pega » Platform » Version: 8.1.8
    cpe:2.3:a:pega:platform:8.1.8
  • Pega » Platform » Version: 8.1.9
    cpe:2.3:a:pega:platform:8.1.9
  • Pega » Platform » Version: 8.2.0
    cpe:2.3:a:pega:platform:8.2.0
  • Pega » Platform » Version: 8.2.1
    cpe:2.3:a:pega:platform:8.2.1


Contact Us

Shodan ® - All rights reserved