PT-2023-2647 · Oracle · Oracle Health Sciences Inform
Published
2023-04-18
·
Updated
2024-09-16
·
CVE-2023-21925
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Oracle Health Sciences InForm versions prior to 6.3.1.3
Oracle Health Sciences InForm versions prior to 7.0.0.1
Description
The issue is related to insufficient input validation in the Core component of Oracle Health Sciences InForm, allowing an unauthenticated attacker with network access via HTTP to compromise the system. Successful attacks can result in a partial denial of service (partial DOS) of Oracle Health Sciences InForm.
Recommendations
For versions prior to 6.3.1.3, update to version 6.3.1.3 or later.
For versions prior to 7.0.0.1, update to version 7.0.0.1 or later.
Fix
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Health Sciences Inform