CVE-2025-58406 PUBLISHED

Lack of HTTP Response Headers

Assigner: CERT-PL
Reserved: 01.09.2025 Published: 02.03.2026 Updated: 02.03.2026

The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor CGM
Product CGM CLININET
Versions Default: unaffected
  • affected from 0 to 2025.MS3 (excl.)

References

Problem Types

  • CWE-693 Protection Mechanism Failure CWE