CVE-2022-32285
14.06.2022, 10:15
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). The affected module is vulnerable to XML External Entity (XXE) attacks due to insufficient input sanitation. This may allow an attacker to disclose confidential data under certain circumstances.Enginsight
Vendor | Product | Version |
---|---|---|
mendix | saml | 𝑥 < 1.16.6 |
mendix | saml | 2.0.0 ≤ 𝑥 < 2.2.2 |
mendix | saml | 3.0.0 ≤ 𝑥 < 3.2.3 |
𝑥
= Vulnerable software versions