← Back to browse · API

CVE-2022-24082

Severity
CRITICAL
CVSS
9.8
EPSS
0.12086
Risk score
43.43
CISA KEV
No
PoC
No
Published
2022-07-19
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-28995, GHSA-3CRJ-J3HG-7V57
Products
Pegasystems:Pega Infinity 8.1.0 <unspecified, Pegasystems:Pega Infinity unspecified <8.7.3
Sources
euvd EUVD-2022-28995

Description

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

References