CVE-2017-16776 describes an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by McKesson Medical Imaging Company (now Change Healthcare). This high-severity vulnerability (CVSS 8.1) allows an attacker to bypass authentication and escalate privileges by sending a malicious HTTP GET request. An unauthenticated attacker can gain limited access to other accounts, while an authenticated attacker can achieve higher privilege access. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and the CVE shows no active exploitation, community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.2CPE matchmatch criteria | cpe:2.3:a:mckesson:conserus_workflow_intelligence:2.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.