CVE-2022-35654: XSS
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35654?
CVE-2022-35654 is a vulnerability affecting Pega Platform from version 8.5.4 to 8.7.3, allowing for XSS attacks with an unauthenticated user and the redirect parameter.
How does CVE-2022-35654 affect Pega Platform?
CVE-2022-35654 affects Pega Platform versions 8.5.4 to 8.7.3 by introducing an XSS vulnerability that can be exploited by an unauthenticated user with the redirect parameter.
What is the severity of CVE-2022-35654?
CVE-2022-35654 has a severity level of medium, with a CVSS score of 6.1.
How can I fix CVE-2022-35654 in Pega Platform 8.5.4 to 8.7.3?
To fix CVE-2022-35654 in Pega Platform 8.5.4 to 8.7.3, apply the recommended hotfix provided by Pega. Refer to the Pega Security Advisory for more information.
Where can I find more information about CVE-2022-35654?
You can find more information about CVE-2022-35654, including the Pega Security Advisory and hotfix matrix, in the provided reference link.