High severity8.1NVD Advisory· Published Dec 13, 2022· Updated Jun 17, 2026
CVE-2022-46664
CVE-2022-46664
Description
A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly handle access control for some module entities.
This could allow authenticated remote attackers to read or delete sensitive information.
Affected products
6- Range: < V2.4.0, < V2.1.4, < V2.3.2
< V2.4.0, < V2.1.4, < V2.3.2+ 4 more
- (no CPE)range: < V2.4.0, < V2.1.4, < V2.3.2
- cpe:2.3:a:siemens:mendix_workflow_commons:*:*:*:*:*:*:*:*range: <2.4.0
- (no CPE)range: All versions < V2.4.0
- (no CPE)range: All versions < V2.1.4
- (no CPE)range: All versions < V2.3.2
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-210822.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.