Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging to other users through manipulation of GET arguments containing document IDs.
This issue has been fixed in 6.09.01.62 version of ADMX.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2026/01/CVE-2025-4596 |
|
History
Thu, 08 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Asseco ADMX system is used for processing medical records. It allows logged in users to access medical files belonging to other users through manipulation of GET arguments containing document IDs. This issue has been fixed in 6.09.01.62 version of ADMX. | |
| Title | Information disclosure via IDOR in Asseco AMDX | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-01-08T15:36:32.702Z
Reserved: 2025-05-12T15:49:49.216Z
Link: CVE-2025-4596
Updated: 2026-01-08T15:36:16.594Z
Status : Awaiting Analysis
Published: 2026-01-08T15:15:43.333
Modified: 2026-01-08T18:08:18.457
Link: CVE-2025-4596
No data.
OpenCVE Enrichment
No data.