← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE EPSS 0.00

Siemens Mendix SAML

View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. The following versions of Siemens Mendix SAML are affected: Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 9.24…

Číst originál na CISA Advisories →

2 zprávy z 2 zdrojů · první 4. 9. 09:55 · poslední 15. 9. 14:00 CZ · EN/orig

Siemens výroba a průmysl US IT

tg: zranitelnost tp: identita

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-80465 8.8 4.0 · siemens 8.7 3.1 · siemens 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 8.7.

Jak se o tom psalo 2

  1. · CISA Advisories US nadpis události

    Siemens Mendix SAML

    View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. The following versions of Siemens Mendix SAML are affected: Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 9.24…

  2. · CSIRT Itálie (ACN) IT

    Siemens: risolta vulnerabilità in Mendix SAML

    Aggiornamenti di sicurezza Siemens sanano una vulnerabilità con gravità "alta" presente nel modulo SAML per Mendix, nota piattaforma aziendale di sviluppo software low-code. Tale vulnerabilità, qualora sfruttata in specifiche configurazioni SSO, potrebbe permettere ad un utente malintenzionato remoto non autenticato, di eludere i meccanismi di autenticazione e le funzionalità di sicurezza sui sistemi interessati.