VYPR
High severity8.1NVD Advisory· Published Dec 13, 2022· Updated Jun 17, 2026

CVE-2022-46664

CVE-2022-46664

Description

A vulnerability has been identified in Mendix Workflow Commons (All versions < V2.4.0), Mendix Workflow Commons V2.1 (All versions < V2.1.4), Mendix Workflow Commons V2.3 (All versions < V2.3.2). Affected versions of the module improperly handle access control for some module entities.

This could allow authenticated remote attackers to read or delete sensitive information.

Affected products

6
  • Range: < V2.4.0, < V2.1.4, < V2.3.2
  • < V2.4.0, < V2.1.4, < V2.3.2+ 4 more
    • (no CPE)range: < V2.4.0, < V2.1.4, < V2.3.2
    • cpe:2.3:a:siemens:mendix_workflow_commons:*:*:*:*:*:*:*:*range: <2.4.0
    • (no CPE)range: All versions < V2.4.0
    • (no CPE)range: All versions < V2.1.4
    • (no CPE)range: All versions < V2.3.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.