CVE-2023-49069: Siemens Mendix

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.11 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.6 (All versions < V10.6.19 only if the basic authentication mechanism is used by the application), Mendix Runtime V8 (All versions < V8.18.33 only if the basic authentication mechanism is used by the application), Mendix Runtime V9 (All versions < V9.24.31 only if the basic authentication mechanism is used by the application). The authentication mechanism of affected applications contains an observable response discrepancy vulnerability when validating usernames. This could allow unauthenticated remote attackers to distinguish between valid and invalid usernames.

Affected products

  • Siemens Mendix: from 8.0, before 9.24.26 (fixed in 9.24.26); from 10.0, before 10.6.12 (fixed in 10.6.12); from 10.7, before 10.12.2 (fixed in 10.12.2); from 10.13, before 10.14.0 (fixed in 10.14.0)
  • Siemens Mendix Runtime v10: before V10.17.0 (fixed in V10.17.0)
  • Siemens Mendix Runtime v10.12: before V10.12.11 (fixed in V10.12.11)
  • Siemens Mendix Runtime v10.6: before V10.6.19 (fixed in V10.6.19)
  • Siemens Mendix Runtime v8: before V8.18.33 (fixed in V8.18.33)
  • Siemens Mendix Runtime v9: before V9.24.31 (fixed in V9.24.31)

Published 2024-09-10. Last modified 2026-06-17.