CVE-2015-4594

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
10/01/2017
Last modified:
20/04/2025

Description

eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclinicalworks:population_health:-:*:*:*:*:*:*:*