CVE-2026-34361
- EPSS 0.04%
- Veröffentlicht 31.03.2026 16:56:11
- Zuletzt bearbeitet 03.04.2026 12:56:06
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attack...
CVE-2026-34360
- EPSS 0.04%
- Veröffentlicht 31.03.2026 16:56:05
- Zuletzt bearbeitet 03.04.2026 13:15:19
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and makes server-s...
CVE-2026-34359
- EPSS 0.02%
- Veröffentlicht 31.03.2026 16:56:01
- Zuletzt bearbeitet 03.04.2026 13:34:11
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authe...
CVE-2024-52007
- EPSS 0.33%
- Veröffentlicht 08.11.2024 23:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!...
CVE-2023-28465
- EPSS 0.74%
- Veröffentlicht 12.12.2023 17:15:07
- Zuletzt bearbeitet 27.05.2025 15:15:29
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name ch...
CVE-2023-24057
- EPSS 0.69%
- Veröffentlicht 26.01.2023 21:18:15
- Zuletzt bearbeitet 01.04.2025 20:15:16
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).