CVE-2022-46664
Published: Dec 13, 2022
Modified: Apr 21, 2025
CVSS v3.1
8.1
Description
A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read or delete sensitive information.
| Vendor | Product | Versions |
|---|---|---|
Siemens | Mendix Workflow Commons | affected All versions < V2.4.0 |
Siemens | Mendix Workflow Commons V2.1 | affected All versions < V2.1.4 |
Siemens | Mendix Workflow Commons V2.3 | affected All versions < V2.3.2 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now