SSA-874353 PUBLISHED CVSS 5.300000190734863 MEDIUM

Affected applications allow for entity enumeration due to distinguishable responses in certain client actions. This could allow an unauthenticated remote attacker to list all valid entities and attribute names of a Mendix Runtime-based application.

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
SiemensMendix Runtime V10.12
SiemensMendix Runtime V9
SiemensMendix Runtime V10.18
SiemensMendix Runtime V8
SiemensMendix Runtime V10.6
SiemensMendix Runtime V10

Timeline

References

Open in Interactive Console →