Impact
An input validation weakness in Pega Platform allows crafted data to be used as a loop condition, potentially causing the application to execute an excessive or infinite loop that consumes CPU and memory until the service becomes unresponsive. This flaw can lead to a denial of service and may also degrade overall system performance.
Affected Systems
Pegasystems Pega Infinity and all Pega Platform releases from version 7.1.0 through 25.1.2 are affected. No specific patch or service pack is identified in the advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available, so the likelihood of exploitation is unknown. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could supply malicious input via exposed user interfaces, API endpoints, or configuration files that influence loop conditions. If successful, the application would experience resource exhaustion and a denial of service.
OpenCVE Enrichment