CVE-2017-12796: Critical severity openmrs vulnerability
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects. The result is that remote unauthenticated users are able to execute operating system commands by crafting malicious XML payloads, as demonstrated by a single admin/reports/reportSchemaXml.form request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12796?
CVE-2017-12796 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2017-12796?
To fix CVE-2017-12796, upgrade to the OpenMRS Reference Application version 2.6.1 or later.
What types of systems are affected by CVE-2017-12796?
CVE-2017-12796 affects OpenMRS versions prior to 2.6.1 that use the Reporting Compatibility Add On before version 2.0.4.
What is the impact of CVE-2017-12796?
The impact of CVE-2017-12796 allows remote unauthenticated users to execute operating system commands on vulnerable OpenMRS instances.
Is user authentication required for exploiting CVE-2017-12796?
No, CVE-2017-12796 does not require user authentication for exploitation, making it particularly dangerous.