CVE-2020-15390: Critical severity pega platform vulnerability
Published Apr 12, 2021
·Updated
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
Affected Software
1 affected component
Pega Pega Platform=8.4.0.237
Event History
Apr 12, 2021
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15390?
CVE-2020-15390 is a security misconfiguration vulnerability in pyActivity in Pega Platform 8.4.0.237 that leads to improper access control.
2
What is the severity of CVE-2020-15390?
The severity of CVE-2020-15390 is critical with a CVSS score of 9.8.
3
How does CVE-2020-15390 occur?
CVE-2020-15390 occurs due to a security misconfiguration in the pyActivity component of Pega Platform 8.4.0.237, which allows for improper access control.
4
What is the affected software of CVE-2020-15390?
The affected software of CVE-2020-15390 is Pega Platform 8.4.0.237.
5
Is there a fix for CVE-2020-15390?
Yes, a fix for CVE-2020-15390 is available. Please refer to the vendor's security advisory or contact the vendor for more information.