The vendor explicitly identifies these products as affected by this CVE.
- Mendix SAML Module (Mendix 7 compatible)
- Mendix SAML Module (Mendix 8 compatible)
- Mendix SAML Module (Mendix 9 compatible)
- Summary
- The affected module is vulnerable to XML External Entity (XXE) attacks due to insufficient input sanitation. This may allow an attacker to disclose confidential data under certain circumstances.
- Remediation
- Update to V1.16.6 or later version
