Database Vulnerability in Philips DoseWise Portal Application
CVE-2017-9656
9.1CRITICAL
Summary
The Philips DoseWise Portal application is affected by a significant security flaw due to the use of hard-coded credentials in its backend database. The affected versions, 1.1.7.333 and 2.1.1.3069, contain credentials that can jeopardize the confidentiality, integrity, and availability of sensitive data stored within the database. An attacker with elevated privileges can exploit this vulnerability to access the backend system files, ultimately allowing unauthorized access to Protected Health Information (PHI) stored in the database. This can lead to serious privacy violations and data breaches if left unaddressed.
Affected Version(s)
DoseWise Portal 1.1.7.333
DoseWise Portal 2.1.1.3069
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved