CVE-2022-34466

MEDIUM

Mendix 9 >=V9.11<V9.15,Mendix 9 V9.12 <V9.12.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime, that can affect the running applications. The vulnerability could allow a malicious user to leak sensitive information in a certain configuration.

Scores

CVSS v3 6.5
EPSS 0.0071
EPSS Percentile 72.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-917 CWE-74
Status published
Products (1)
mendix/mendix 9.11.0 - 9.15.0
Published Jul 12, 2022
Tracked Since Feb 18, 2026