CVE 3.3 LOW

Medical Informatics Engineering Enterprise Health includes session token in debug output_CVE-2025-35031

3.3 / 10
LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Description

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.

Basic Information

ID CVE-2025-35031
Source cisa-cg
Published Sep 29, 2025 at 20:00

Affected Product

Vendor Medical Informatics Engineering
Product Enterprise Health
Version RC202503
Affected Versions Medical Informatics Engineering Enterprise Health RC202503
Medical Informatics Engineering Enterprise Health RC202409
Medical Informatics Engineering Enterprise Health RC202403

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.