ICSA-23-075-05
The Mendix SAML module insufficiently verifies the SAML assertions. This could allow unauthenticated remote attackers to bypass authentication and get access to the application. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. Note: For compatibility reasons, fixes for several versions of the Mendix SAML module were introduced in two release steps: - The first fix versions address CVE-2023-25957. It removes the vulnerability, except when the recommended, default configuration option 'Use Encryption' is disabled. - The second fix versions address CVE-2023-29129, which removes the issue for the non default configuration as well.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mendix SAML (Mendix 9.12/9.18 compatible, Upgrade Track) | ||
| Mendix SAML (Mendix 8 compatible) | ||
| Mendix SAML (Mendix 9 latest compatible, Upgrade Track) | ||
| Mendix SAML (Mendix 7 compatible) | ||
| Mendix SAML (Mendix 9.6 compatible, New Track) | ||
| Mendix SAML (Mendix 9 latest compatible, New Track) | ||
| Mendix SAML (Mendix 9.12/9.18 compatible, New Track) | ||
| Mendix SAML (Mendix 9.6 compatible, Upgrade Track) |
Timeline
- Mar 14, 2023 CVE Published
- May 6, 2025 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-851884.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-851884.html advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-851884.pdf advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-851884.txt advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-075-05.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-075-05 advisory
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://marketplace.mendix.com/link/component/1174 fix