← Vulnerability feed

Vulnerability record · CVE-2022-24082 · published 19 July 2022

CVE-2022-24082: Pega infinity deserialization of untrusted data vulnerability

Pega · Infinity

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

9.8 CVSS 3.1 Critical EPSS 12% · top 3.9% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24082 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-10094Pega infinity code injection vulnerabilityPega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of CodeEPSS 0.48%9.8CVE-2022-24083Pega infinity improper authorization vulnerabilityPassword authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.EPSS 0.91%9.8CVE-2021-27651Pega Infinity password reset bypasses local authenticationPega Infinity versions 8.2.1 through 8.5.2 contain an improper authentication flaw in the password reset function for local accounts. The reset flow …EPSS 54%analysed7.8CVE-2021-27654Pega infinity weak password recovery vulnerabilityForgotten password reset functionality for local accounts can be used to bypass local authentication checks.EPSS 0.60%4.9CVE-2021-27653Pega infinity improper access control vulnerabilityMisconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data exposure.EPSS 1.1%4.8CVE-2024-10716Pega infinity cross-site scripting vulnerabilityPega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.EPSS 0.22%4.8CVE-2024-6702Pega infinity injection vulnerabilityPega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.EPSS 0.26%4.8CVE-2024-6700Pega infinity cross-site scripting vulnerabilityPega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2022-24082), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.