The M2M Broker in OSEHRA VistA, as distributed before September 30, 2013, allows attackers to bypass authentication and authorization to perform doctor-only actions and read or modify patient records via unspecified vectors related to a "logic flaw."
References
Configurations
History
21 Nov 2024, 02:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.darkreading.com/vulnerability/anatomy-of-an-electronic-health-record-e/240164441/ - | |
References | () http://www.osehra.org/blog/m2m-broker-security-patch - Patch | |
References | () http://www.osehra.org/blog/vista-patch-available-osehra - |
Information
Published : 2013-12-04 22:55
Updated : 2024-11-21 02:00
NVD link : CVE-2013-6945
Mitre link : CVE-2013-6945
CVE.ORG link : CVE-2013-6945
JSON object : View
Products Affected
osehra
- vista
CWE
CWE-264
Permissions, Privileges, and Access Controls