Philips healthcare infomatics solution vulnerable to SQL injection

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
The Philips Tasy EMR, used by hundreds of hospitals as a medical record solution and healthcare management system, is vulnerable to two critical SQL injection flaws.
The vulnerabilities are tracked as CVE-2021-39375 and CVE-2021-39376, and both have a severity score of 8.8 in CVSS v3.

These are SQL injection flaws via two parameters, relying on the improper escaping of special characters in SQL commands.

The affected versions of the product are Tasy EMR HTML5 3.06.1803 and prior, so all organizations using the healthcare suite are urged to upgrade to version 3.06.1804 or later.
CISA has also released an advisory for the product, as it's widely deployed in many public and private health institutes, mainly in Argentina, Brazil, Colombia, Mexico, and the Dominican Republic.

"Organizations observing any suspected malicious activity should follow their established internal procedures and report their findings to CISA for tracking and correlation against other incidents," warned the advisory from CISA.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top