Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.
Solution:
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01 | third party advisory us government resource |
https://www.philips.com/a-w/security/security-advisories/product-security-2020.html#2020_archive |