CVE-2021-31341
MEDIUMMendix Database Replication < 7.0.1 - Information Disclosure via Malformed XML Table Mapping
Title source: llmDescription
Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-05
Third Party Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-919955.pdf
Scores
CVSS v3
4.3
EPSS
0.0072
EPSS Percentile
49.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-209
Status
published
Products (1)
mendix/database_replication
< 7.0.1
Published
May 12, 2021
Tracked Since
Feb 18, 2026