QID 982239
QID 982239: Java (maven) Security Update for ca.uhn.hapi.fhir:hapi-fhir-jpaserver-base (GHSA-67f6-c8mx-4q2m)
JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full index scan, with an accompanying large amount of server resources if there are many simultaneous history requests.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-67f6-c8mx-4q2m for updates pertaining to this vulnerability.
Vendor References
- GHSA-67f6-c8mx-4q2m -
github.com/advisories/GHSA-67f6-c8mx-4q2m
CVEs related to QID 982239
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-67f6-c8mx-4q2m | ca.uhn.hapi.fhir:hapi-fhir-jpaserver-base |
|