« Volver al listado

CVE-2022-25650

Estado: ModificadaMedia (6.5)—

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All versions < V8.18.14), Mendix Applications using Mendix 9 (All versions < V9.12.0), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.3). When querying the database, it is possible to sort the results using a protected field. With this an authenticated attacker could extract information about the contents of a protected field.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-25650",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 7",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V7.23.27"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 8",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V8.18.14"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 9",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V9.12.0"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 9 (V9.6)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V9.6.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-12T09:15:14.543",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-870917.pdf",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-870917.pdf",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications using Mendix 8 (All versions < V8.18.14), Mendix Applications using Mendix 9 (All versions < V9.12.0), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.3). When querying the database, it is possible to sort the results using a protected field. With this an authenticated attacker could extract information about the contents of a protected field."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en las aplicaciones de Mendix usando Mendix 7 (todas las versiones anteriores a V7.23.27), las aplicaciones de Mendix usando Mendix 8 (todas las versiones anteriores a V8.18.14), las aplicaciones de Mendix usando Mendix 9 (todas las versiones anteriores a V9.12.0), las aplicaciones de Mendix usando Mendix 9 (V9.6) (todas las versiones anteriores a V9.6.3). Cuando es consultada la base de datos, es posible ordenar los resultados usando un campo protegido. Con esto un atacante autenticado podría extraer información sobre el contenido de un campo protegido"
    }
  ],
  "lastModified": "2026-06-17T04:33:50.293",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2547E594-D1AA-4D03-B8DE-612C0FC81C64",
              "versionEndExcluding": "7.23.27",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19F81FC8-0502-4A75-B3C7-E4CCE634B7B7",
              "versionEndExcluding": "8.18.14",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDAACA5B-273A-4512-8646-C5B56BA3AF76",
              "versionEndExcluding": "9.12.0",
              "versionStartIncluding": "9.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}