Publication Date: 2022-03-08
Last Update: 2022-04-12
Current Version: V1.1
CVSS v3.1 Base Score: 6.8

Affected Product and Versions Remediation
Mendix Applications using Mendix 7:
All versions < V7.23.29
Update to V7.23.29 or later version and redeploy your application
https://docs.mendix.com/releasenotes/studio-pro/7.23/
Mendix Applications using Mendix 8:
All versions < V8.18.16
Update to V8.18.16 or later version and redeploy your application
https://docs.mendix.com/releasenotes/studio-pro/8.18/
Mendix Applications using Mendix 9:
All deployments with Runtime Custom Setting DataStorage.UseNewQueryHandler set to False
Set Runtime Custom Setting DataStorage.UseNewQueryHandler to True or remove the custom setting. The value is set to True by default
https://docs.mendix.com/developerportal/deploy/environments-details#runtime-tab

CVSS v3.1 Base Score 6.8
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
CWE: CWE-284: Improper Access Control

https://www.siemens.com/cert/advisories