« Volver al listado

CVE-2023-23835

Estado: ModificadaAlta (7.5)—

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.10), Mendix Applications using Mendix 9 (V9.18) (All versions < V9.18.4), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.15). Some of the Mendix runtime API’s allow attackers to bypass XPath constraints and retrieve information using XPath queries that trigger errors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-23835",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-23835",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-20T16:18:41.457961Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "productcert@siemens.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 7",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V7.23.34"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 8",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V8.18.23"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 9",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V9.22.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 9 (V9.12)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V9.12.10"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 9 (V9.18)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V9.18.4"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "Mendix Applications using Mendix 9 (V9.6)",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V9.6.15"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-02-14T11:15:14.687",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-252808.pdf",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-252808.pdf",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.34), Mendix Applications using Mendix 8 (All versions < V8.18.23), Mendix Applications using Mendix 9 (All versions < V9.22.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.10), Mendix Applications using Mendix 9 (V9.18) (All versions < V9.18.4), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.15). Some of the Mendix runtime API’s allow attackers to bypass XPath constraints and retrieve information using XPath queries that trigger errors."
    }
  ],
  "lastModified": "2026-06-17T05:38:04.730",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43E9E16C-936B-47D4-B5C1-30EAF7F6B8AE",
              "versionEndExcluding": "7.23.34",
              "versionStartIncluding": "7.0.2"
            },
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A1ED592-BD7C-43FB-812E-15F579F8F40E",
              "versionEndExcluding": "8.18.23",
              "versionStartIncluding": "8.0.0"
            },
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3CFFFE6-F0CD-4C06-B3D7-44F3FA84B346",
              "versionEndExcluding": "9.6.15",
              "versionStartIncluding": "9.0.0"
            },
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFBB912C-5B70-436C-A615-717C6C90E25C",
              "versionEndExcluding": "9.12.10",
              "versionStartIncluding": "9.7.0"
            },
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AC5D595-F345-4533-BF6D-451CAFF17E13",
              "versionEndExcluding": "9.18.4",
              "versionStartIncluding": "9.18.0"
            },
            {
              "criteria": "cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B9D7FEC-9D09-4CFD-AD46-880655E27898",
              "versionEndExcluding": "9.22.0",
              "versionStartIncluding": "9.19.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}