PT-2013-6196 · Osehra · Osehra Vista

Publicado

2013-12-04

·

Atualizado

2014-02-25

·

CVE-2013-6945

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OSEHRA VistA versions prior to September 30, 2013
Description The issue allows attackers to bypass authentication and authorization, enabling them to perform actions restricted to doctors and access or modify patient records. This is due to a logic flaw, although the specific vectors related to this flaw are not specified.
Recommendations For OSEHRA VistA versions prior to September 30, 2013, update to a version released after September 30, 2013, to resolve the issue. As a temporary workaround, consider restricting access to sensitive patient records and doctor-only actions until the update can be applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6945

Produtos afetados

Osehra Vista