Description
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.
Problem types
CWE-1295 Debug Messages Revealing Unnecessary Information
Product status
RC202503 before RC202503 2025-04-08
RC202409 before RC202409 2025-04-08
RC202403 before RC202403 2025-04-08
RC202503 2025-04-08
RC202409 2025-04-08
RC202403 2025-04-08
Credits
George Thompson, Sandia National Laboratories
Trevor LaPay, Sandia National Laboratories
Fernando Martinez, Sandia National Laboratories
Gary Huang, Sandia National Laboratories
References
raw.githubusercontent.com/...IT/white/2025/va-25-272-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-35031 (url)