CVE-2025-40571

low

Description

A vulnerability has been identified in Mendix OIDC SSO (Mendix 10 compatible) (All versions < V4.0.0), Mendix OIDC SSO (Mendix 9 compatible) (All versions). The Mendix OIDC SSO module grants read and write access to all tokens exclusively to the Administrator role and could result in privilege misuse by an adversary modifying the module during Mendix development.

References

https://cert-portal.siemens.com/productcert/html/ssa-726617.html

Details

Source: Mitre, NVD

Published: 2025-05-13

Updated: 2025-05-13

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:N/AC:H/Au:M/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 2.2

Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

Severity: Low

CVSS v4

Base Score: 2.1

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Severity: Low

EPSS

EPSS: 0.00023