PT-2019-14652 · Pegasystems · Pega Platform

Published

2019-11-26

·

Updated

2024-08-05

·

CVE-2019-16387

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PEGA Platform version 8.3.0
Description The issue allows a low-privilege account to perform actions and retrieve data that should only be accessible to an administrator. This can be achieved by sending a direct request to the "prweb/sso/random token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema ListDatabases" API endpoint.
Recommendations For PEGA Platform version 8.3.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2019-16387

Affected Products

Pega Platform