PT-2021-2781 · Mendix · Mendix

Published

2021-04-15

·

Updated

2021-04-22

·

CVE-2021-27394

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mendix Applications using Mendix 7 versions prior to 7.23.19 Mendix Applications using Mendix 8 versions prior to 8.17.0 Mendix Applications using Mendix 8 (V8.12) versions prior to 8.12.5 Mendix Applications using Mendix 8 (V8.6) versions prior to 8.6.9 Mendix Applications using Mendix 9 versions prior to 9.0.5
Description A vulnerability has been identified that allows authenticated, non-administrative users to modify their privileges by manipulating the user role under certain circumstances, allowing them to gain administrative privileges. This issue is related to errors in privilege management. Exploitation of the vulnerability may allow a remote attacker to elevate their privileges and gain unauthorized access to protected information.
Recommendations For Mendix 7, update to version 7.23.19 or later. For Mendix 8, update to version 8.17.0 or later. For Mendix 8 (V8.12), update to version 8.12.5 or later. For Mendix 8 (V8.6), update to version 8.6.9 or later. For Mendix 9, update to version 9.0.5 or later.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02324
CVE-2021-27394

Affected Products

Mendix