Publication Date: 2021-04-14
Last Update: 2021-04-14
Current Version: V1.0
CVSS v3.1 Base Score: 8.1

Affected Product and Versions Remediation
Mendix Applications using Mendix 7:
All versions < V7.23.19
Update your Mendix Project to V7.23.19 or later version and redeploy your application
https://docs.mendix.com/releasenotes/studio-pro/7.23
Mendix Applications using Mendix 8:
All versions < V8.17.0
Update your Mendix Project to V8.17.0 or later version and redeploy your application
https://docs.mendix.com/releasenotes/studio-pro/8.17
Mendix Applications using Mendix 8 (V8.12):
All versions < V8.12.5
Update your Mendix Project to V8.12.5 or later and preferably the latest V8.18 version and redeploy your application
https://docs.mendix.com/releasenotes/studio-pro/8.12
Mendix Applications using Mendix 8 (V8.6):
All versions < V8.6.9
Update your Mendix Project to V8.6.9 or later and preferably the latest V8.18 version and redeploy your application
https://docs.mendix.com/releasenotes/studio-pro/8.6
Mendix Applications using Mendix 9:
All versions < V9.0.5
Update your Mendix Project to V9.0.5 or later version and redeploy your application
https://docs.mendix.com/releasenotes/studio-pro/9.0

CVSS v3.1 Base Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
CWE: CWE-269: Improper Privilege Management

https://www.siemens.com/cert/advisories