Vulnerability in Oracle Health Sciences InForm by Oracle
CVE-2023-21922

6.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

The vulnerability in Oracle Health Sciences InForm allows an unauthenticated attacker with HTTP network access to compromise the application. Although it is challenging to exploit, successful attempts require human interaction from a user other than the attacker. This can result in unauthorized creation, deletion, or modification of critical data, allowing an attacker to gain access to sensitive information. This vulnerability affects supported versions prior to 6.3.1.3 and 7.0.0.1, posing significant risks to the integrity and confidentiality of Oracle Health Sciences InForm data.

Affected Version(s)

Health Sciences InForm * < 6.3.1.3

Health Sciences InForm * < 7.0.0.1

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.