Password Bypass Vulnerability in Mendix Applications by Mendix
CVE-2022-31257

7.5HIGH

Summary

A vulnerability exists in Mendix applications that could allow an attacker with access to an active user session to bypass password validation. This flaw affects multiple versions of Mendix 7, 8, and 9, enabling the attacker to potentially set weak passwords, compromising user security. Organizations using the affected versions should take immediate measures to update their applications to mitigate this risk.

Affected Version(s)

Mendix Applications using Mendix 7 All versions < V7.23.31

Mendix Applications using Mendix 8 All versions < V8.18.18

Mendix Applications using Mendix 9 All versions < V9.14.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.