CVE-2021-27394: High severity mendix vulnerability
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions < V8.12.5), Mendix Applications using Mendix 8 (V8.6) (All versions < V8.6.9), Mendix Applications using Mendix 9 (All versions < V9.0.5). Authenticated, non-administrative users could modify their privileges by manipulating the user role under certain circumstances, allowing them to gain administrative privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27394?
CVE-2021-27394 is a vulnerability in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions < V8.12.5), and Mendix Applications using Mendix 8 (V8.6) (All versions < V8.6.9).
What is the severity level of CVE-2021-27394?
CVE-2021-27394 has a severity level of 8.8, which is considered high.
What software versions are affected by CVE-2021-27394?
Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications using Mendix 8 (All versions < V8.17.0), Mendix Applications using Mendix 8 (V8.12) (All versions < V8.12.5), and Mendix Applications using Mendix 8 (V8.6) (All versions < V8.6.9) are affected by CVE-2021-27394.
How can I fix CVE-2021-27394?
To fix CVE-2021-27394, it is recommended to update Mendix Applications to at least the following versions: V7.23.19 for Mendix 7, V8.17.0 for Mendix 8, V8.12.5 for Mendix 8 (V8.12), and V8.6.9 for Mendix 8 (V8.6).
Where can I find more information about CVE-2021-27394?
More information about CVE-2021-27394 can be found at the following reference link: [https://cert-portal.siemens.com/productcert/pdf/ssa-875726.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-875726.pdf).