PT-2023-2648 · Oracle · Oracle Health Sciences Inform

Published

2023-04-18

·

Updated

2023-04-20

·

CVE-2023-21926

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Health Sciences InForm versions prior to 6.3.1.3 Oracle Health Sciences InForm versions prior to 7.0.0.1
Description The issue is related to insufficient input validation in the Core component of Oracle Health Sciences InForm. It allows an unauthenticated attacker with logon to the infrastructure where Oracle Health Sciences InForm executes to compromise the system. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access to critical data or complete access to all Oracle Health Sciences InForm accessible data.
Recommendations For versions prior to 6.3.1.3, update to version 6.3.1.3 or later. For versions prior to 7.0.0.1, update to version 7.0.0.1 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-02488
CVE-2023-21926

Affected Products

Oracle Health Sciences Inform