CVE-2022-46823: XSS
A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V3.3.0 < V3.3.8). The affected module is vulnerable to reflected cross-site scripting (XSS) attacks. This could allow an attacker to extract sensitive information by tricking users into accessing a malicious link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46823?
The severity of CVE-2022-46823 is critical.
Which versions of Mendix SAML are affected by CVE-2022-46823?
All versions >= V2.3.0 < V2.3.4 of Mendix SAML (Mendix 8 compatible), and all versions >= V3.3.0 < V3.3.9 of Mendix SAML (Mendix 9 compatible, New Track) and Mendix SAML (Mendix 9 compatible, Upgrade Track) are affected by CVE-2022-46823.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-46823?
The Common Weakness Enumeration (CWE) ID for CVE-2022-46823 is 79.
How can I fix CVE-2022-46823?
To fix CVE-2022-46823, it is recommended to update Mendix SAML to version V2.3.4 for Mendix 8 compatible and versions V3.3.9 for Mendix 9 compatible (New Track) and Mendix 9 compatible (Upgrade Track).
Where can I find more information about CVE-2022-46823?
You can find more information about CVE-2022-46823 in the official Siemens Cert-Portal advisory at https://cert-portal.siemens.com/productcert/pdf/ssa-496604.pdf.