PT-2013-6196 · Osehra · Osehra Vista
Published
2013-12-04
·
Updated
2014-02-25
·
CVE-2013-6945
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OSEHRA VistA versions prior to September 30, 2013
Description
The issue allows attackers to bypass authentication and authorization, enabling them to perform actions restricted to doctors and access or modify patient records. This is due to a logic flaw, although the specific vectors related to this flaw are not specified.
Recommendations
For OSEHRA VistA versions prior to September 30, 2013, update to a version released after September 30, 2013, to resolve the issue. As a temporary workaround, consider restricting access to sensitive patient records and doctor-only actions until the update can be applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Osehra Vista