CVE-2022-34466
MEDIUMMendix 9 >=V9.11<V9.15,Mendix 9 V9.12 <V9.12.3 - Info Disclosure
Title source: llmDescription
A vulnerability has been identified in Mendix Applications using Mendix 9 (All versions >= V9.11 < V9.15), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.3). An expression injection vulnerability was discovered in the Workflow subsystem of Mendix Runtime, that can affect the running applications. The vulnerability could allow a malicious user to leak sensitive information in a certain configuration.
Scores
CVSS v3
6.5
EPSS
0.0071
EPSS Percentile
72.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-917
CWE-74
Status
published
Products (1)
mendix/mendix
9.11.0 - 9.15.0
Published
Jul 12, 2022
Tracked Since
Feb 18, 2026