CVE-2023-50168: XEE
Published Mar 14, 2024
·Updated
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
Affected Software
2 affected components
Pega Pega Platform>=6.0<8.8.4
Pega Pega Platform<8.8.5
Event History
Mar 14, 2024
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50168?
CVE-2023-50168 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-50168?
To remediate CVE-2023-50168, update to a version of Pega Platform that is 8.8.5 or later.
3
What types of issues does CVE-2023-50168 introduce?
CVE-2023-50168 introduces an XML External Entity (XXE) vulnerability affecting PDF Generation functionality.
4
Which versions of Pega Platform are affected by CVE-2023-50168?
CVE-2023-50168 affects Pega Platform versions from 6.x up to and including 8.8.4.
5
Is CVE-2023-50168 exploitable remotely?
Yes, CVE-2023-50168 can be exploited remotely if the affected software is misconfigured.