QID 591200
Date Published: 2022-12-08
QID 591200: Siemens Mendix (Update B) Sensitive Information Disclosure Vulnerability (icsa-22-104-07, SSA-414513)
AFFECTED PRODUCTS
The following versions of Mendix, a software platform to build mobile and web applications, are affected:
Mendix applications using Mendix 7: All versions prior to 7.23.31
Mendix applications using Mendix 8: All versions prior to 8.18.18
Mendix applications using Mendix 9: All versions prior to 9.11
Mendix applications using Mendix 9 (v9.6): All versions prior to 9.6.12
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to read sensitive data.
Customers are advised to refer to CERT MITIGATIONS section icsa-22-104-07 for affected packages and patching details.
- icsa-22-104-07 -
www.cisa.gov/uscert/ics/advisories/icsa-22-104-07
CVEs related to QID 591200
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| icsa-22-104-07 |
|
||
| ssa-414513 |
|