CVE-2019-16374: Critical severity pega platform vulnerability
Pega Platform 8.2.1 allows LDAP injection because a username can contain a character and can be of unlimited length. An attacker can specify four characters of a username, followed by the character, to bypass access control.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16374?
CVE-2019-16374 is a vulnerability in Pega Platform 8.2.1 that allows LDAP injection by using a username with a * character.
How severe is CVE-2019-16374?
CVE-2019-16374 is classified as a critical vulnerability with a severity rating of 9.8 out of 10.
How does CVE-2019-16374 work?
CVE-2019-16374 allows an attacker to bypass access control by specifying a username with four characters followed by the * character.
How can I fix CVE-2019-16374?
To fix CVE-2019-16374, upgrade to a version of Pega Platform that is not affected by this vulnerability.
Where can I find more information about CVE-2019-16374?
You can find more information about CVE-2019-16374 on the Pega Community website and the GitHub Gist page.