Vulnerabilities > CVE-2019-16374 - Unspecified vulnerability in Pega Platform 8.1.7/8.1.8/8.2.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |