CVE-2021-42025
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio Pro do not properly control write access for certain client actions. This could allow authenticated attackers to manipulate the content of System.FileDocument objects in some cases, regardless whether they have write access to it.
Se ha identificado una vulnerabilidad en las aplicaciones de Mendix usadas en Mendix versión 8 (Todas las versiones anteriores a V8.18.13), aplicaciones de Mendix usadas en Mendix versión 9 (Todas las versiones anteriores a V9.6.2). Las aplicaciones construidas con las versiones afectadas de Mendix Studio Pro no controlan apropiadamente el acceso de escritura para determinadas acciones del cliente. Esto podría permitir a atacantes autenticados manipular el contenido de los objetos System.FileDocument en algunos casos, independientemente de que tengan acceso de escritura
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-06 CVE Reserved
- 2021-11-09 CVE Published
- 2023-06-02 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-779699.pdf | 2021-11-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mendix Search vendor "Mendix" | Mendix Search vendor "Mendix" for product "Mendix" | >= 8.0.0 < 8.18.13 Search vendor "Mendix" for product "Mendix" and version " >= 8.0.0 < 8.18.13" | - |
Affected
| ||||||
Mendix Search vendor "Mendix" | Mendix Search vendor "Mendix" for product "Mendix" | >= 9.0.0 < 9.6.2 Search vendor "Mendix" for product "Mendix" and version " >= 9.0.0 < 9.6.2" | - |
Affected
|