QID 591328
Date Published: 2023-02-07
QID 591328: Siemens Mendix Improper Access Control Vulnerability (SSA-433782)
An improper access control vulnerability in Mendix applications was discovered.
In case of access to an active user session, the vulnerability could allow changing that user password bypassing password validations within a Mendix application.
AFFECTED PRODUCTS
The following versions of Mendix, a software platform to build mobile and web applications, are affected:
Mendix applications using Mendix 7: All versions prior to 7.23.31
Mendix applications using Mendix 8: All versions prior to 8.18.18
Mendix applications using Mendix 9: All versions prior to 9.14.0
Mendix applications using Mendix 9 (v9.6): All versions prior to 9.6.12
Mendix applications using Mendix 9 (v9.12): All versions prior to 9.12.2
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
On Successful exploitation, the vulnerability could allow changing that user password by bypassing password validations within a Mendix application.
Customers are advised to refer to CERT MITIGATIONS section SSA-43378 for affected packages and patching details.
CVEs related to QID 591328
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-43378 |
|