CVE Vulnerabilities

CVE-2022-31257

Published: Jul 12, 2022 | Modified: Jul 24, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12). In case of access to an active user session in an application that is built with an affected version, it’s possible to change that user’s password bypassing password validations within a Mendix application. This could allow to set weak passwords.

Affected Software

Name Vendor Start Version End Version
Mendix Mendix 7.0.0 (including) 7.32.31 (excluding)
Mendix Mendix 8.0.0 (including) 8.18.18 (excluding)
Mendix Mendix 9.6.0 (including) 9.6.12 (excluding)
Mendix Mendix 9.12.0 (including) 9.12.2 (excluding)
Mendix Mendix 9.13.0 (including) 9.14.0 (excluding)

References