Known vulnerabilities in Mendix SAML Module
Vendor:
Siemens
Software:
Mendix SAML Module
Software CPE:
cpe:2.3:a:siemens:mendix_saml_module:*:*:*:*:*:*:*:*
Website:
https://www.siemens.com/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU116393 - Improper Verification of Cryptographic Signature CVE-2025-40758 |
CWE-347 | High | 3.6.21, 4.0.3, 4.1.2 | 02.10.2025 |
SB2025100226 |
||
| #VU67302 - Authentication Bypass by Capture-replay CVE-2022-37011 |
CWE-294 | Medium | 1.17.0, 2.3.0, 3.3.1 | 14.09.2022 |
SB2022091431 |
||
| #VU64407 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-32286 |
CWE-79 | Low | 1.16.6, 2.2.2, 3.2.3 | 15.06.2022 |
SB2022061520 |
||
| #VU64403 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2022-32285 |
CWE-611 | Medium | 1.16.6, 2.2.2, 3.2.3 | 15.06.2022 |
SB2022061520 |
||
| #VU54019 - Insufficient Verification of Data Authenticity CVE-2021-33712 |
CWE-345 | Medium | 2.1.2 | 10.06.2021 |
SB2021061006 |