The vendor explicitly identifies these products as affected by this CVE.
- Mendix Runtime V8
- Mendix Runtime V9
- Mendix Runtime V10
- Mendix Runtime V10.6
- Mendix Runtime V10.12
- Summary
- The basic authentication implementation of affected applications contains a race condition vulnerability which could allow unauthenticated remote attackers to circumvent default account lockout measures.
- Remediation
- Update to V10.12.7 or later version
