Unauthenticated Access Vulnerability in Oracle Life Sciences Argus Safety
CVE-2025-21570
6.1MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 January 2025
Summary
An unauthenticated access vulnerability exists in the Oracle Life Sciences Argus Safety product, which is part of Oracle Health Sciences Applications. This vulnerability can be exploited by an attacker with network access via HTTP to compromise the application. The attack requires human interaction from a third-party user, potentially leading to unauthorized updates, inserts, or deletions of accessible data. Additionally, there is a risk of unauthorized read access to certain sensitive data within Oracle Life Sciences Argus Safety. While the vulnerability is specific to this product, its implications may extend to other products in its ecosystem.
Affected Version(s)
Oracle Life Sciences Argus Safety 8.2.3
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved