VulnerabilityModified
CVE-2017-11356
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.
MEDIUM 6.5EPSS 3.50%
Does this matter?
Lower severity and a low EPSS score (3.50%). Track it; it rarely justifies an emergency change on its own.
Description
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.50% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- pega/pega platform
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2017/Jul/28Mailing List, Third Party Advisory
- https://pdn.pega.com/pegasystems-security-bulletin-cve-2017-11355-and-cve-2017-11356/pegasystems-security-bulletin-cve
- https://www.exploit-db.com/exploits/42335/
- http://seclists.org/fulldisclosure/2017/Jul/28Mailing List, Third Party Advisory
- https://pdn.pega.com/pegasystems-security-bulletin-cve-2017-11355-and-cve-2017-11356/pegasystems-security-bulletin-cve
- https://www.exploit-db.com/exploits/42335/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.