CVE-2019-16386

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
26/11/2019
Last modified:
05/08/2024

Description

PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=random_harness_id request to get database schema information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:* 7.1.0 (including) 7.4.0 (including)
cpe:2.3:a:pega:pega_platform:*:*:*:*:*:*:*:* 8.1.0 (including) 8.3.1 (including)


References to Advisories, Solutions, and Tools