URGENT and IMMEDIATE action required
A critical vulnerability was identified in the Apache Commons Text software on October 13, 2022 (CVE-2022-42889). This vulnerability could allow malicious actors to perform string interpolation to trigger network access or code execution.
Pega software leverages the Commons Text component in two places in the Pega Platform software.
- Within the Search and Reporting Service (SRS)
- Within the Decision Strategy Manager (DSM) Text Analytics component
This vulnerability can affect Pega clients running on versions 8.2.1 through to 8.8 of Pega Infinity. We are not aware of any of our clients being compromised as a result of this vulnerability.
To block malicious actors from exploiting this vulnerability, Pega has created the I22 Hotfix for each relevant version to remediate this issue. These are listed in the table below.
As always, be sure you have appropriate backups in place before applying the hotfix. Note that a system restart will be required for the hotfix to take effect.
Clients should deploy the hotfix in a lower environment and test there before propagating across systems. Pega recommends that the hotfix should NOT be committed until you have validated any impact.
As always, we recommend our clients review our Security Checklist regularly.
Pega will be providing more detailed advice to clients via their Client Advisory [CAD-] cases in My Support Portal.
Hotfixes:
Version |
Hotfix |
8.2.1 |
HFIX-84501 |
8.2.2 |
HFIX-84503 |
8.2.3 |
HFIX-84505 |
8.2.4 |
HFIX-84507 |
8.2.5 |
HFIX-84509 |
8.2.6 |
HFIX-84522 |
8.2.7 |
HFIX-84524 |
8.2.8 |
HFIX-84526 |
8.3.0 |
HFIX-84550 |
8.3.1 |
HFIX-84530 |
8.3.2 |
HFIX-84533 |
8.3.3 |
HFIX-84534 |
8.3.4 |
HFIX-84536 |
8.3.5 |
HFIX-84537 |
8.3.6 |
HFIX-84539 |
8.4.0 |
HFIX-84540 |
8.4.1 |
HFIX-84542 |
8.4.2 |
HFIX-84543 |
8.4.3 |
HFIX-84549 |
8.4.4 |
HFIX-84545 |
8.4.5 |
HFIX-84548 |
8.4.6 |
HFIX-84547 |
8.5.1 |
HFIX-84546 |
8.5.2 |
HFIX-84544 |
8.5.3 |
HFIX-84541 |
8.5.4 |
HFIX-84538 |
8.5.5 |
HFIX-84535 |
8.5.6 |
HFIX-84532 |
8.6.0 |
HFIX-84531 |
8.6.1 |
HFIX-84529 |
8.6.2 |
HFIX-84527 |
8.6.3 |
HFIX-84525 |
8.6.4 |
HFIX-84523 |
8.6.5 |
HFIX-84521 |
8.7.0 |
HFIX-84520 |
8.7.1 |
HFIX-84508 |
8.7.2 |
HFIX-84506 |
8.7.3 |
HFIX-84504 |
8.7.4 |
Included in release |
8.8.0 |
HFIX-84502 |