First published: Fri Apr 16 2021(Updated: )
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions < V8.12.5), Mendix Applications using Mendix 8 (V8.6) (All versions < V8.6.9), Mendix Applications using Mendix 9 (All versions < V9.0.5). Authenticated, non-administrative users could modify their privileges by manipulating the user role under certain circumstances, allowing them to gain administrative privileges.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mendix | >=7.0.2<7.23.19 | |
Mendix | >=8.0.0<8.17.0 | |
Mendix | >=9.0.0<9.0.5 | |
Mendix | >=8.6.0<8.6.9 | |
Mendix | >=8.12.0<8.12.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27394 is a vulnerability in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions < V8.12.5), and Mendix Applications using Mendix 8 (V8.6) (All versions < V8.6.9).
CVE-2021-27394 has a severity level of 8.8, which is considered high.
Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions < V8.12.5), and Mendix Applications using Mendix 8 (V8.6) (All versions < V8.6.9) are affected by CVE-2021-27394.
To fix CVE-2021-27394, it is recommended to update Mendix Applications to at least the following versions: V7.23.19 for Mendix 7, V8.17.0 for Mendix 8, V8.12.5 for Mendix 8 (V8.12), and V8.6.9 for Mendix 8 (V8.6).
More information about CVE-2021-27394 can be found at the following reference link: [https://cert-portal.siemens.com/productcert/pdf/ssa-875726.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-875726.pdf).