CVE-2015-4594: Eclinicalworks Population Health

Critical severity, CVSS 9.8. EPSS: 6.2% chance of exploitation in the next 30 days.

eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

Affected products

Published 2017-01-10. Last modified 2026-06-17.