CVE-2022-35655: XSS
Published Aug 22, 2022
·Updated
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
Affected Software
1 affected component
Pega Pega Platform>=7.3<=8.7.3
Event History
Aug 22, 2022
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-35655?
CVE-2022-35655 is an XSS issue in Pega Platform versions 7.3 to 8.7.3 due to a misconfiguration of a datapage setting.
2
How does CVE-2022-35655 impact Pega Platform users?
CVE-2022-35655 can allow attackers to execute malicious scripts in a Pega Platform application, potentially leading to unauthorized access, data theft, or other malicious activities.
3
How severe is CVE-2022-35655?
CVE-2022-35655 has a severity keyword of 'medium' and a severity value of 6.1.
4
Which versions of Pega Platform are affected by CVE-2022-35655?
Pega Platform versions 7.3 to 8.7.3 are affected by CVE-2022-35655.
5
How can I fix CVE-2022-35655?
To fix CVE-2022-35655, it is recommended to apply the relevant hotfix provided by Pega Platform. More information can be found in the Pega Security Advisory.