QID 591198
Date Published: 2023-01-19
QID 591198: Siemens Mendix XPath Constraint Vulnerability (SSA-148641)
A XPath Constraint vulnerability in the Mendix Runtime was discovered, that can affect the running applications.
AFFECTED PRODUCTS
The following versions of Mendix, a software platform to build mobile and web applications, are affected:
Mendix applications using Mendix 7: All versions prior to 7.23.29
Mendix applications using Mendix 8: All versions prior to 8.18.16
Mendix applications using Mendix 9: All versions
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
The vulnerability could allow a malicious user to deduce contents of inaccessible attributes and modify sensitive data.
Customers are advised to refer to CERT MITIGATIONS section SSA-148641 for affected packages and patching details.
CVEs related to QID 591198
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-148641 |
|