CVE-2022-25650: Medium severity mendix vulnerability
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All versions < V8.18.14), Mendix Applications using Mendix 9 (All versions < V9.12.0), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.3). When querying the database, it is possible to sort the results using a protected field. With this an authenticated attacker could extract information about the contents of a protected field.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-25650?
CVE-2022-25650 is a vulnerability identified in Mendix Applications using Mendix 7, 8, and 9.
What versions of Mendix Applications are affected by CVE-2022-25650?
All versions of Mendix 7 < V7.23.27, Mendix 8 < V8.18.14, and Mendix 9 < V9.12.0 are affected.
What is the severity of CVE-2022-25650?
CVE-2022-25650 has a severity value of 6.5, which is classified as medium.
How can I fix CVE-2022-25650?
To fix CVE-2022-25650, update your Mendix Applications to a version that is equal to or greater than the fixed versions: V7.23.27 for Mendix 7, V8.18.14 for Mendix 8, and V9.12.0 for Mendix 9.
Where can I find more information about CVE-2022-25650?
You can find more information about CVE-2022-25650 in the reference provided: https://cert-portal.siemens.com/productcert/pdf/ssa-870917.pdf