The vendor explicitly identifies these products as affected by this CVE.
- Mendix Applications using Mendix 7
- Mendix Applications using Mendix 8
- Mendix Applications using Mendix 9
- Mendix Applications using Mendix 9 (V9.6)
- Summary
- When querying the database, it is possible to sort the results using a protected field. With this an authenticated attacker could extract information about the contents of a protected field.
- Remediation
- Update your Mendix Project to V7.23.27 or later version and redeploy your application
