CVE-2017-12796

critical
Published 2017-10-23 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects. The result is that remote unauthenticated users are able to execute operating system commands by crafting malicious XML payloads, as demonstrated by a single admin/reports/reportSchemaXml.form request.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://wiki.openmrs.org/display/RES/Release+Notes+2.6.1

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://talk.openmrs.org/t/critical-security-advisory-2017-09-12/13291

Application impact

VendorProductVersionsFixed
openmrsopenmrs{"endExcluding":"2.6.1"}2.6.1

References

CWEs

CWE-502

Verify integrity in audit chain (admin only). AS-IS.