CVE-2022-46664

CVSS V2 None CVSS V3 None
Description
A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read or delete sensitive information.
Overview
  • CVE ID
  • CVE-2022-46664
  • Assigner
  • productcert@siemens.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2022-12-13T16:15:26
  • Last Modified Date
  • 2023-01-10T12:15:23
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:siemens:mendix_workflow_commons:*:*:*:*:*:*:*:* 1 OR 2.4.0
References
History
Created Old Value New Value Data Type Notes
2022-12-13 16:18:31 Added to TrackCVE
2022-12-13 17:22:10 2022-12-13T16:15:26.040 2022-12-13T16:15:26 CVE Published Date updated
2022-12-13 17:22:10 2022-12-13T17:15:17 CVE Modified Date updated
2022-12-13 17:22:10 Received Awaiting Analysis Vulnerability Status updated
2022-12-13 17:22:10 A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read or delete sensitive information. A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read or delete sensitive information. Description updated
2022-12-15 04:15:10 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-18 04:35:14 2022-12-16T15:08:12 CVE Modified Date updated
2022-12-18 04:35:14 Undergoing Analysis Analyzed Vulnerability Status updated
2022-12-18 04:35:18 NVD-CWE-Other Weakness Enumeration new
2022-12-18 04:35:23 CPE Information updated
2023-01-10 12:20:05 2023-01-10T12:15:23 CVE Modified Date updated
2023-01-10 12:20:05 Analyzed Modified Vulnerability Status updated
2023-01-10 12:20:07 Weakness Enumeration update
2023-01-10 12:20:07 A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read or delete sensitive information. A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read or delete sensitive information. Description updated