CVE-2025-9559: Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data
Published Oct 16, 2025
·Updated
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only be used to read data.
Affected Software
4 affected components
Pega Pega Platform>=8.7.5<24.2.2
Pega Pega Platform>=7.1.0<23.1.5
Pega Pega Platform>=24.1.0<=24.1.3
Pega Pega Platform>=24.2.0<=24.2.2
Event History
Oct 16, 2025
CVE Published
via MITRE·03:28 PM
Data Sourced
via MITRE·03:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 27, 57989
Event
via FIRST·06:27 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-9559?
The severity of CVE-2025-9559 is rated as medium due to the potential for unauthorized data access.
2
How do I fix CVE-2025-9559?
To fix CVE-2025-9559, update Pega Platform to a version newer than 24.2.2 or implement the recommended security patches.
3
Which versions of Pega Platform are affected by CVE-2025-9559?
CVE-2025-9559 affects Pega Platform versions 8.7.5 to 24.2.2.
4
What type of vulnerability is CVE-2025-9559?
CVE-2025-9559 is classified as an Insecure Direct Object Reference vulnerability.
5
What can happen if CVE-2025-9559 is exploited?
If CVE-2025-9559 is exploited, attackers may gain unauthorized access to sensitive data within the affected user interface component.