Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31257

Опубликовано: 12 июл. 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12). In case of access to an active user session in an application that is built with an affected version, it’s possible to change that user’s password bypassing password validations within a Mendix application. This could allow to set weak passwords.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.32.31 (исключая)
cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.18.18 (исключая)
cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 9.6.0 (включая) до 9.6.12 (исключая)
cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 9.12.0 (включая) до 9.12.2 (исключая)
cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 9.13.0 (включая) до 9.14.0 (исключая)

EPSS

Процентиль: 41%
0.00195
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12). In case of access to an active user session in an application that is built with an affected version, it’s possible to change that user’s password bypassing password validations within a Mendix application. This could allow to set weak passwords.

EPSS

Процентиль: 41%
0.00195
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other