Publication Date: 2022-06-14
Last Update: 2022-06-14
Current Version: V1.0
CVSS v3.1 Base Score: 8.3

Affected Product and Versions Remediation
Mendix SAML Module (Mendix 7 compatible):
All versions < V1.16.6
Update to V1.16.6 or later version
https://marketplace.mendix.com/link/component/1174/
Mendix SAML Module (Mendix 8 compatible):
All versions < V2.2.2
Update to V2.2.2 or later version
https://marketplace.mendix.com/link/component/1174/
Mendix SAML Module (Mendix 9 compatible):
All versions < V3.2.3
Update to V3.2.3 or later version
https://marketplace.mendix.com/link/component/1174/

For applications upgraded to Mendix 9 from earlier Mendix versions, the issues have already been resolved in V3.2.2

CVSS v3.1 Base Score 8.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L/E:P/RL:O/RC:C
CWE: CWE-611: Improper Restriction of XML External Entity Reference

CVSS v3.1 Base Score 7.6
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

https://www.siemens.com/cert/advisories