QID 590946
Date Published: 2022-11-16
QID 590946: Siemens Mendix Improper Access Control Vulnerability (ICSA-22-104-17)
AFFECTED PRODUCTS
The following versions of Mendix, a software platform to build mobile and web applications, are affected:
Mendix applications using Mendix 7: All versions prior to 7.23.27
Mendix applications using Mendix 8: All versions prior to 8.18.14
Mendix applications using Mendix 9: All versions prior to 9.12.0
Mendix applications using Mendix 9 (9.6): All versions prior to 9.6.3
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of this vulnerability could allow an authenticated attacker to extract information from a database protected field.
Customers are advised to refer to CERT MITIGATIONS section ICSA-22-104-17 for affected packages and patching details.
- ICSA-22-104-17 -
www.us-cert.gov/ics/advisories/ICSA-22-104-17
CVEs related to QID 590946
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-22-104-17 |
|