CVE-2022-32285: XEE
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). The affected module is vulnerable to XML External Entity (XXE) attacks due to insufficient input sanitation. This may allow an attacker to disclose confidential data under certain circumstances.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-32285.
What is the severity of CVE-2022-32285?
The severity of CVE-2022-32285 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2022-32285?
The affected software versions are Mendix SAML Module (Mendix 7 compatible) versions < V1.16.6, Mendix SAML Module (Mendix 8 compatible) versions < V2.2.2, and Mendix SAML Module (Mendix 9 compatible) versions < V3.2.3.
What is the vulnerability in Mendix SAML Module (Mendix 7 compatible)?
The vulnerability is an XML External Entity (XXE) vulnerability.
How can I fix CVE-2022-32285?
To fix CVE-2022-32285, it is recommended to update the affected Mendix SAML Module to a version that is higher than the mentioned vulnerable versions.