CVE-2019-16388 describes an information disclosure vulnerability in PEGA Platform 8.3.0. It allows an attacker to access audit log information by directly requesting prweb/sso/random_token/!STANDARD?pyStream=MyAlerts. The vendor clarified this access requires an administrator account, not a low-privilege one as initially claimed. The vulnerability has a CVSS score of 4.3 (Medium), indicating low attack complexity and no user interaction required, but only leads to limited confidentiality impact (information disclosure) without affecting integrity or availability. The attack vector is network-based. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The CVE has received minimal community discussion and media coverage, suggesting low public awareness and a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3CPE matchmatch criteria | cpe:2.3:a:pega:pega_platform:8.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.