Improper Authorization in Mendix Applications using Mendix 8 and Mendix Applications using Mendix 9 - CVE-2021-42025
Published: November 18, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to applications built with affected versions of Mendix Studio Pro do not properly control write access for certain client actions. A remote authenticated attacker can manipulate the content of specific objects regardless of whether they have write access.
Affected software
Mendix Applications using Mendix 9
How to mitigate CVE-2021-42025
Mendix Applications using Mendix 9 - update to 9.6.2