CVE-2024-10094
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Nov 20, 2024
Updated: Nov 21, 2024
CWE ID 94
Summary
CVE-2024-10094 is a cybersecurity vulnerability affecting versions 6.x to Infinity 24.1.1 of Pega Platform. This issue involves Improper Control of Generation of Code, allowing an attacker to inject malicious code and potentially gain unauthorized access to sensitive data or systems. Successful exploitation could lead to significant security breaches and potential business disruption. It's crucial for organizations using these affected versions to apply the necessary patches or updates as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Pega Infinity
Affected Vendors
- Pegasystems