vendor:
Pega Platform
by:
Marcin Wolak
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: Pega Platform
Affected Version From: 8.1.2000
Affected Version To: 8.3.2007
Patch Exists: YES
Related CWE: CVE-2022-24082
CPE: a:pega:pega_platform
Platforms Tested: Red Hat Enterprise 7
2022
Pega Platform 8.1.0 – Remote Code Execution (RCE)
Pega Platform 8.1.0 is vulnerable to Remote Code Execution (RCE). An attacker can exploit this vulnerability by using MOGWAI LABS JMX Exploitation Toolkit and jython to install mbean for remote code execution and execute commands such as id and ifconfig.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update the Pega Platform to the latest version.