QID 591415
QID 591415: Siemens Mendix Expression Injection Vulnerability (SSA-492173)
An improper access control vulnerability in Mendix applications was discovered.
In case of access to an active user session, the vulnerability could allow changing that user password bypassing password validations within a Mendix application.
AFFECTED PRODUCTS
The following versions of Mendix, a software platform to build mobile and web applications, are affected:
Mendix applications using Mendix 9: V9.11 upto V9.15
Mendix applications using Mendix 9 (v9.12): prior to V9.12.3
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"
Successful exploitation of this vulnerability could allow a malicious user to leak sensitive information if the Workflow visual language of Mendix is used.
Customers are advised to refer to CERT MITIGATIONS section SSA-492173 for affected packages and patching details.
CVEs related to QID 591415
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-492173 |
|