PT-2026-34144 · Oracle · Oracle Life Sciences Inform+1

Published

2026-04-21

·

Updated

2026-04-26

·

CVE-2026-34323

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Oracle Life Sciences InForm versions 7.0.1.0 through 7.0.1.1
Description An issue exists in the IDM Authentication component of Oracle Life Sciences InForm. An unauthenticated attacker with network access via HTTP can compromise the system, although successful exploitation requires human interaction. This can lead to unauthorized read access to a subset of data, unauthorized update, insert, or delete access to certain accessible data, and the ability to cause a partial denial of service (DoS), which is a condition where the system becomes partially unavailable to users.
Recommendations For versions 7.0.1.0 through 7.0.1.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-34323

Affected Products

Oracle Life Sciences Inform
Life Sciences Inform