SSA-638652 PUBLISHED CVSS 7.400000095367432 HIGH

The Mendix SAML module insufficiently protects from packet capture replay. This could allow unauthorized remote attackers to bypass authentication and get access to the application. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. Note: For compatibility reasons, fix versions are introduced in two release steps: - The first fix versions address CVE-2022-37011. It removes the vulnerability, except when the not recommended, non default configuration option 'Allow Idp Initiated Authentication' is enabled. - The second fix versions address CVE-2022-44457, which removes the issue for the non default configuration as well.

Risk Scores

CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
Mendix SAML (Mendix 7 compatible)
Mendix SAML (Mendix 8 compatible)
Mendix SAML (Mendix 9 compatible, New Track)
Mendix SAML (Mendix 9 compatible, Upgrade Track)

Timeline

References

Open in Interactive Console →