CVE-2019-16386: Medium severity pega platform vulnerability
DISPUTED PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/randomtoken/!STANDARD?pyActivity=GetWebInfo&target=popup&pzHarnessID=randomharnessid request to get database schema information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-16386.
What is the severity of CVE-2019-16386?
The severity of CVE-2019-16386 is medium with a CVSS score of 4.3.
Which software versions are affected by CVE-2019-16386?
PEGA Platform 7.x versions between 7.1.0 and 7.4.0, as well as PEGA Platform 8.x versions between 8.1.0 and 8.3.1 are affected by CVE-2019-16386.
How does CVE-2019-16386 work?
CVE-2019-16386 allows an attacker to disclose information by making a specific request to the PEGA Platform using a low-privilege account.
Is there a fix available for CVE-2019-16386?
At the moment, there is no provided fix for CVE-2019-16386. Please refer to the vendor's response for more information.