PT-2022-16457 · Pegasystems · Pega Platform

Marcin Wolak

·

Published

2022-07-19

·

Updated

2022-11-07

·

CVE-2022-24082

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pega Platform (affected versions not specified)
Description The issue arises when an on-premise installation of the Pega Platform has the JMX interface port exposed to the Internet without proper port filtering configuration. This could allow the upload of serialized payloads to attack the underlying system. Systems running on PegaCloud are not affected due to their design and architecture.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-24082

Affected Products

Pega Platform