First published: Wed Apr 23 2025(Updated: )
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NIH BRICS | <=14.0.0-67 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27581 is considered a high severity vulnerability due to unauthorized access to sensitive modules.
To remediate CVE-2025-27581, ensure that user roles are correctly configured to restrict access to the InET module.
CVE-2025-27581 allows unauthorized users to execute direct requests that could lead to data exposure and unauthorized actions.
Organizations using NIH BRICS versions up to 14.0.0-67 are affected by CVE-2025-27581.
The potential consequences of CVE-2025-27581 include data breaches and unauthorized access to sensitive research information.