#VU94196 Use of Hard-coded, Security-relevant Constants in Mendix Encryption - CVE-2024-39888
Published: July 12, 2024
Mendix Encryption
Siemens
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected module defines a specific hard-coded default value for the EncryptionKey constant, which is used in projects where no individual EncryptionKey was specified. A remote attacker can gain unauthorized access to sensitive information on the system.