Known vulnerabilities in Mendix Applications using Mendix 9

Vendor: Siemens
Software CPE: cpe:2.3:a:siemens:mendix_applications_using_mendix_9:*:*:*:*:*:*:*:*
Total vulnerabilities: 11
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Mendix Applications using Mendix 9 Mendix Applications using Mendix 9 is affected by 11 known vulnerabilities: 7 medium, 4 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU91991 - Improper Privilege Management
CVE-2024-33500
CWE-269 Low
No
No
9.24.22 12.06.2024 SB2024061226
#VU83214 - Authentication Bypass by Capture-replay
CVE-2023-45794
CWE-294 Medium
No
No
9.24.10 16.11.2023 SB2023111606
#VU72460 - Improper Access Control
CVE-2023-23835
CWE-284 Medium
No
No
9.6.15, 9.12.10, 9.18.4, 9.22.0 21.02.2023 SB2023022138
#VU65270 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2022-34466
CWE-74 Medium
No
No
9.12.3, 9.15 13.07.2022 SB2022071330
#VU65265 - Improper Access Control
CVE-2022-31257
CWE-284 Low
No
No
9.6.12, 9.12.2, 9.14.0 13.07.2022 SB2022071325
#VU62383 - Exposure of sensitive information to an unauthorized actor
CVE-2022-27241
CWE-200 Medium
No
No
9.11 19.04.2022 SB2022041909
#VU62382 - Improper Access Control
CVE-2022-25650
CWE-284 Low
No
No
8.18.14, 9.6.3 19.04.2022 SB2022041908
#VU61236 - Improper Access Control
CVE-2022-24309
CWE-284 Medium
No
No
- 10.03.2022 SB2022031009
#VU58242 - Improper Authorization
CVE-2021-42026
CWE-285 Low
No
No
9.6.2 18.11.2021 SB2021111818
#VU58241 - Improper Authorization
CVE-2021-42025
CWE-285 Medium
No
No
9.6.2 18.11.2021 SB2021111818
#VU58197 - Use of Web Browser Cache Containing Sensitive Information
CVE-2021-42015
CWE-525 Medium
No
No
9.6.1 16.11.2021 SB2021111621