CVE-2022-31257: High severity mendix vulnerability
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12). In case of access to an active user session in an application that is built with an affected version, it’s possible to change that user’s password bypassing password validations within a Mendix application. This could allow to set weak passwords.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mendix vulnerability?
The vulnerability ID for this Mendix vulnerability is CVE-2022-31257.
What is the severity of CVE-2022-31257?
The severity of CVE-2022-31257 is high with a severity value of 7.5.
Which versions of Mendix are affected by CVE-2022-31257?
CVE-2022-31257 affects Mendix 7 (All versions < V7.23.31), Mendix 8 (All versions < V8.18.18), Mendix 9 (All versions < V9.14.0), and Mendix 9 (V9.12) (All versions < V9.12.2).
How can I fix CVE-2022-31257?
To fix CVE-2022-31257, update your Mendix application to versions V7.23.31, V8.18.18, V9.14.0, or V9.12.2 depending on the affected version.
Where can I find more information about CVE-2022-31257?
You can find more information about CVE-2022-31257 at the following reference: [Siemens ProductCERT](https://cert-portal.siemens.com/productcert/pdf/ssa-433782.pdf).