Password Bypass Vulnerability in Mendix Applications by Mendix
CVE-2022-31257
7.5HIGH
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 12 July 2022
What is CVE-2022-31257?
A vulnerability exists in Mendix applications that could allow an attacker with access to an active user session to bypass password validation. This flaw affects multiple versions of Mendix 7, 8, and 9, enabling the attacker to potentially set weak passwords, compromising user security. Organizations using the affected versions should take immediate measures to update their applications to mitigate this risk.
Affected Version(s)
Mendix Applications using Mendix 7 All versions < V7.23.31
Mendix Applications using Mendix 8 All versions < V8.18.18
Mendix Applications using Mendix 9 All versions < V9.14.0