Skip to main content


         This documentation site is for previous versions. Visit our new documentation site for current releases.      
 

This content has been archived and is no longer being updated.

Links may not function; however, this content may be relevant to outdated versions of the product.

Pega Sales Automation modified rules for BAC prevention (7.4-8.3)

Updated on September 10, 2021

Broken Access control (BAC) refers to all access control issues in web applications that allow end users to gain unauthorized access to privileged data and functionality. Open Web Application Security Project (OWASP) identifies BAC as one of the top 10 security vulnerabilities. BAC usually occurs when users can bypass access control checks by leveraging vulnerabilities such as uniform resource locator (URL)-based requests that do not verify user privileges.

In the 8.3 release, Pega Sales Automation has modified the rules that call secured activities in the Pega Platform. The query strings and parameters in the calls are registered so that they cannot be tampered by the end users.

For more information about the enhancements to prevent Broken Access Control (BAC), see Protecting the application layer.

To see additional modified rules for the Pega Sales Automation industry applications, see the following articles:

Attached at the bottom of the article are all modified rules for Pega Sales Automation for Insurance 8.5. If you have overridden any of these rules in your Pega Sales Automation implementation layer, you need to update them with the changed rules.

The following list shows the modified rules for Pega Sales Automation 8.3. If you have overridden any of these rules in your Pega Sales Automation implementation layer, you need to update them with the changed rules.

    #Rule typeRule nameClass nameAvailableRuleset version
    1Rule-NavigationcrmWorkMenuPegaCRM-Work-SFA-LeadYesPegaCRM-SFA:08-03-01
    2Rule-NavigationcrmWorkMenuPegaCRM-Work-SFA-Lead-IndYesPegaCRM-SFA:08-03-01
    3Rule-HTML-SectionAccountsHeaderInOrgPegaCRM-Entity-OrgYesPegaCRM-SFA:08-03-01
    4Rule-NavigationContactMenuPegaCRM-Entity-ContactYesPegaCRM-SFA:08-03-01
    5Rule-HTML-SectioncrmOperatorsInPartnerPegaCRM-Entity-Org-PartnerYesPegaCRM-SFA:08-03-01
    6Rule-Obj-FlowcrmCreatePegaCRM-UserMaintenance-YesPegaCRM-SFA:08-03-01
    7Rule-HTML-SectionpyUserDashboardHeaderData-PortalYesSA-Specialization:08-03-01
    8Rule-HTML-SectioncrmUserDashboardemplateThreeColumn@baseclassYesPegaCRM-SFA:08-03-01
    9Rule-HTML-SectioncrmUserDashboardemplateTwoColumn@baseclassYesPegaCRM-SFA:08-03-01
    10Rule-File-Textwebwb • crm_dashboard_postaction • js YesPegaCRM-SFA:08-03-01
    11Rule-HTML-SectionIconsPegaCRM-Entity-ContactYesPegaCRM-SFA:08-03-01
    12Rule-NavigationcrmRelatedLeads_NavigationPegaCRM-Entity-YesPegaCRM-SFA:08-03-01
    13Rule-NavigationLeadMenuPegaCRM-Work-SFA-LeadYesPegaCRM-SFA:08-03-01
    14Rule-NavigationOrgsMenuPegaCRM-Entity-OrgYesPegaCRM-SFA:08-03-01
    15Rule-HTML-SectionOpportunityHeaderPegaCRM-Entity-ContactYesPegaCRM-SFA:08-03-01
    16Rule-NavigationcrmRelatedOpps_NavigationPegaCRM-Entity-YesPegaCRM-SFA:08-03-01
    17Rule-NavigationOppMenuPegaCRM-Work-SFA-OpportunityYesPegaCRM-SFA:08-03-01
    18Rule-HTML-SectionViewOrganizationNBADataPegaCRM-Data-NextBestActionsYesSA-Artifacts:08-03-01
    19Rule-NavigationcrmWorkMenuPegaCRM-Entity-OrgYesPegaCRM-SFA:08-03-01
    20Rule-NavigationcrmWorkMenuPegaCRM-Work-FundRequestYesPegaCRM-SFA:08-03-01
    21Rule-NavigationcrmWorkMenuPegaCRM-Work-SFA-Opportunity-IndYesPegaCRM-SFA:08-03-01
    22Rule-NavigationcrmWorkMenuPegaCRM-Work-SFA-OpportunityYesPegaCRM-SFA:08-03-01
    23Rule-HTML-SectionOpportunitiesCreateButtons_MobilePegaCRM-Work-YesPegaCRM-SFA:08-03-01
    24Rule-HTML-SectionpyWorkGetNextWorkWork-YesPegaCRM-SFA:08-03-01
    25Rule-NavigationSFAPortalMenuItems_MobilePegaCRM-PortalYesPegaCRM-SFA:08-03-01
    26Rule-HTML-PropertycrmStageProcessLink YesPegaCRM-SFA:08-03-01
    27Rule-NavigationcrmWorkMenuPegaCRM-Entity-ContactYesPegaCRM-SFA:08-03-01
    28Rule-NavigationRecipientsMenuPegaCRM-Entity-ContactYesPegaCRM-SFA:08-03-01
    29Rule-HTML-SectioncrmSubmitAndCancelPegaCRM-Work-YesPegaCRM-SFA:08-03-01
    30Rule-HTML-SectioncrmSubmitAndCancelPegaCRM-Work-SFA-LeadYesPegaCRM-SFA:08-03-01
    • Previous topic Integrating Pega Sales Automation with Gmail by using the Chrome extension
    • Next topic Deprecated and withdrawn rules and table changes in Pega Sales Automation (7.4-'23)

    Have a question? Get answers now.

    Visit the Support Center to ask questions, engage in discussions, share ideas, and help others.

    Did you find this content helpful?

    Want to help us improve this content?

    We'd prefer it if you saw us at our best.

    Pega.com is not optimized for Internet Explorer. For the optimal experience, please use:

    Close Deprecation Notice
    Contact us