Vulnerability Description
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP request to the vulnerable service allows for arbitrary file read access to the local file system as well as the transmittal of the application service's account hashed credentials to a remote attacker.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Changehealthcare | Conserus Image Repository | 2.1.1.105 |
Related Weaknesses (CWE)
References
- https://technical.nttsecurity.com/post/102emjg/conserus-image-repository-xml-extThird Party Advisory
- https://technical.nttsecurity.com/post/102emjg/conserus-image-repository-xml-extThird Party Advisory
FAQ
What is CVE-2017-14101?
CVE-2017-14101 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change He...
How severe is CVE-2017-14101?
CVE-2017-14101 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-14101?
Check the references section above for vendor advisories and patch information. Affected products include: Changehealthcare Conserus Image Repository.