CVE-2025-4596
Unknown
Unknown - Not Provided
Insecure Direct Object Reference in Asseco ADMX Enables Unauthorized Medical Record Access
Publication date: 2026-01-08
Last updated on: 2026-01-08
Assigner: CERT.PL
Description
Description
Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging to other users through manipulation of GET arguments containing document IDs.
This issue has been fixed in 6.09.01.62 version of ADMX.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| asseco | admx | 6.09.01.62 |
| asseco | amdx | to 6.09.01.62 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |