CVE-2023-25957
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML (Mendix 9 latest compatible, Upgrade Track) (All versions >= V3.1.8 < V3.3.0), Mendix SAML (Mendix 9.6 compatible, New Track) (All versions >= V3.1.9 < V3.2.7), Mendix SAML (Mendix 9.6 compatible, Upgrade Track) (All versions >= V3.1.8 < V3.2.6). The affected versions of the module insufficiently verify the SAML assertions. This could allow unauthenticated remote attackers to bypass authentication and get access to the application.
For compatibility reasons, fix versions still contain this issue, but only when the recommended, default configuration option `'Use Encryption'` is disabled.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-02-17 CVE Reserved
- 2023-03-14 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-303: Incorrect Implementation of Authentication Algorithm
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-851884.pdf | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mendix Search vendor "Mendix" | Saml Search vendor "Mendix" for product "Saml" | >= 1.16.4 < 1.17.2 Search vendor "Mendix" for product "Saml" and version " >= 1.16.4 < 1.17.2" | mendix |
Affected
| ||||||
Mendix Search vendor "Mendix" | Saml Search vendor "Mendix" for product "Saml" | >= 2.2.0 < 2.2.3 Search vendor "Mendix" for product "Saml" and version " >= 2.2.0 < 2.2.3" | mendix |
Affected
| ||||||
Mendix Search vendor "Mendix" | Saml Search vendor "Mendix" for product "Saml" | >= 3.1.9 < 3.2.5 Search vendor "Mendix" for product "Saml" and version " >= 3.1.9 < 3.2.5" | mendix |
Affected
|