CVE-2024-10094: Code Injection
Published Nov 20, 2024
·Updated
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
Affected Software
10 affected components
Pega Pega Platform>=6.0<24.1.1
Pega Infinity>=6.0<8.1.9
Pega Infinity>=8.2<8.2.8
Pega Infinity>=8.3.0<8.3.6
Pega Infinity>=8.4.0<8.4.6
Pega Infinity>=8.5<8.5.6
Pega Infinity>=8.6.0<8.6.6
Pega Infinity>=8.7.0<=8.8.5
Pega Infinity>=23.1.0<23.1.4
Pega Infinity>=24.1.0<24.1.2
Event History
Nov 20, 2024
CVE Published
via MITRE·02:45 PM
Data Sourced
via MITRE·02:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-10094?
CVE-2024-10094 is rated as a high-severity vulnerability due to its potential impact on code execution.
2
How do I fix CVE-2024-10094?
To remediate CVE-2024-10094, update the Pega Platform to a version greater than 24.1.1.
3
What versions of Pega Platform are affected by CVE-2024-10094?
CVE-2024-10094 affects Pega Platform versions from 6.x up to and including 24.1.1.
4
What type of vulnerability is CVE-2024-10094?
CVE-2024-10094 is classified as an Improper Control of Generation of Code vulnerability.
5
Can CVE-2024-10094 lead to arbitrary code execution?
Yes, CVE-2024-10094 has the potential to allow attackers to execute arbitrary code on affected systems.