Lucene search

K
cvelistSiemensCVELIST:CVE-2022-32286
HistoryJun 14, 2022 - 9:22 a.m.

CVE-2022-32286

2022-06-1409:22:20
CWE-79
siemens
www.cve.org
3
mendix saml module
xss attacks
cross site scripting
error message sanitation
cve-2022-32286

EPSS

0.001

Percentile

31.3%

A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (All versions < V2.2.2), Mendix SAML Module (Mendix 9 compatible) (All versions < V3.2.3). In certain configurations SAML module is vulnerable to Cross Site Scripting (XSS) attacks due to insufficient error message sanitation. This could allow an attacker to execute malicious code by tricking users into accessing a malicious link.

CNA Affected

[
  {
    "product": "Mendix SAML Module (Mendix 7 compatible)",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V1.16.6"
      }
    ]
  },
  {
    "product": "Mendix SAML Module (Mendix 8 compatible)",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V2.2.2"
      }
    ]
  },
  {
    "product": "Mendix SAML Module (Mendix 9 compatible)",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions < V3.2.3"
      }
    ]
  }
]

EPSS

0.001

Percentile

31.3%

Related for CVELIST:CVE-2022-32286