VDB

SSA-874353

SSA-874353 PUBLISHED CVSS 5.300000190734863 MEDIUM

Affected applications allow for entity enumeration due to distinguishable responses in certain client actions. This could allow an unauthenticated remote attacker to list all valid entities and attribute names of a Mendix Runtime-based application.

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
SiemensMendix Runtime V10.12
SiemensMendix Runtime V9
SiemensMendix Runtime V10.18
SiemensMendix Runtime V8
SiemensMendix Runtime V10.6
SiemensMendix Runtime V10

Timeline

  • Apr 8, 2025 CVE Published
  • Jun 10, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›