nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-35031 CVE-2025-35031
MEDIUM
Medical Informatics Engineering Enterprise Health includes session token in debug output
Record summary
CVE-2025-35031 has a selected CVSS score of 4.6 (medium).
Description
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 30, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Enterprise HealthBrowse Medical Informatics Engineering / Enterprise HealthDefault status: unknown | CVE List | RC202503 to < RC202503 2025-04-08 | affected |
| RC202409 to < RC202409 2025-04-08 | affected | ||
| RC202403 to < RC202403 2025-04-08 | affected | ||
| RC202503 2025-04-08 | unaffected | ||
| RC202409 2025-04-08 | unaffected | ||
| RC202403 2025-04-08 | unaffected |
References
3url
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json url
https://www.cve.org/CVERecord?id=CVE-2025-35031