Multiple Vulnerabilities in PEGA Infinity Platform
An attacker could distinguish between valid and invalid usernames based on the server’s response time which can be used for username enumeration in the PEGA Infinity platform. An weak brute force protection enabled password spraying attacks, in which the same password is tested against many different usernames, potentially granting unauthorized access to user accounts. Additionally, an Insecure Direct Object Reference (IDOR) vulnerability could be used to read image files from other users without setting the option to share the images with others.
CVE-2025-62181, CVE-2025-9559


