CVE-2025-35032

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mieweb:enterprise_health:rc202303:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202309:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202403:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202409:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202503:*:*:*:*:*:*:*

History

02 Jan 2026, 20:31

Type Values Removed Values Added
First Time Mieweb enterprise Health
Mieweb
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json - Third Party Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-35032 - () https://www.cve.org/CVERecord?id=CVE-2025-35032 - Third Party Advisory
CPE cpe:2.3:a:mieweb:enterprise_health:rc202303:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202403:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202309:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202409:*:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202503:*:*:*:*:*:*:*

29 Sep 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-29 20:15

Updated : 2026-01-02 20:31


NVD link : CVE-2025-35032

Mitre link : CVE-2025-35032

CVE.ORG link : CVE-2025-35032


JSON object : View

Products Affected

mieweb

  • enterprise_health
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type