Description
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, including administrators.
Problem types
CWE-335 Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
Product status
Any version
References
github.com/...e/src/main/java/gov/nih/tbi/CoreConstants.java
github.com/...ccount/service/complex/AccountManagerImpl.java
github.com/...ty.Research/blob/main/CVE-2025-27580/README.md