CVE detail
CVE-2019-16388 — CVE-2019-16388
Published 2019-11-26 · Modified 2026-06-17 · Vendor pega · Product pega_platform · Source nvd
MEDIUM
severity
CVSS-derived band
0.0072
EPSS probability
exploitation probability, 30d
50.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAlerts request to get Audit Log information while using a low-privilege account. NOTE: The vendor states that this vulnerability was discovered using an administrator account and they are normal administrator functions. Therefore, the claim that the CVE was done with a low privilege account is incorrect
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References