Improper Authorization in Mendix Applications using Mendix 8 and Mendix Applications using Mendix 9 - CVE-2021-42026
Published: November 18, 2021
Mendix Applications using Mendix 8
Mendix Applications using Mendix 9
Siemens
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to applications built with affected versions of Mendix Studio Pro do not properly control read access for certain client actions. A remote authenticated attacker can retrieve specific attributes of arbitrary objects, regardless of whether they have read access.