---
id: CVE-2025-35032
title: >-
  Medical Informatics Engineering Enterprise Health allows authenticated users
  to upload arbitrary files
summary: >-
  Medical Informatics Engineering Enterprise Health allows authenticated users
  to upload arbitrary files. The impact of this behavior depends on how files
  are accessed. This issue is fixed as of 2025-04-08.
severity: low
cvss: 3.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N'
cwe:
  - CWE-434
vendor: mieweb
product: enterprise_health
affected:
  - enterprise_health = rc202303
  - enterprise_health = rc202309
  - enterprise_health = rc202403
  - enterprise_health = rc202409
  - enterprise_health = rc202503
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-35032'
references:
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-35032'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.00253
epssPercentile: 0.15441
ingestedAt: '2026-10-09T09:31:00.989Z'
---

## Overview

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.

## Affected

- `enterprise_health = rc202303`
- `enterprise_health = rc202309`
- `enterprise_health = rc202403`
- `enterprise_health = rc202409`
- `enterprise_health = rc202503`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
