Tenable discovered two security vulnerabilities in Microsoft's Azure Health Bot service. The first vulnerability, found in the "Data Connections" feature, allowed unauthorized access to resources.
Microsoft released a new vulnerability and patched Azure Health Bot, a managed artificial intelligence-enabled cloud platform healthcare organizations use to develop virtual healthcare assistants.
Multiple privilege escalation issues in Microsoft Azure's cloud-based Health Bot service opened the platform to server-side request forgery (SSRF) and could have allowed access to cross-tenant ...