Description
Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authentication). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Life Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Life Sciences InForm accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Life Sciences InForm. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).
Published: 2026-04-21
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized data modification and partial denial of service
Action: Assess & Mitigate
AI Analysis

Impact

The IDM Authentication component in Oracle Life Sciences InForm versions 7.0.1.0 and 7.0.1.1 contains a flaw that allows an unauthenticated attacker who can reach the system over HTTP to perform unauthorized update, insert or delete operations on data and read data that should be protected, as well as to cause a partial denial of service. The flaw results in modest confidentiality, integrity and availability impact as reflected in a CVSS 3.1 base score of 6.3 (C:L/I:L/A:L).

Affected Systems

Affected systems include Oracle Corporation’s Life Sciences InForm application, specifically versions 7.0.1.0 and 7.0.1.1.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity, and because the EPSS is not available, the likelihood of exploitation is unclear. The vulnerability must be exploited through HTTP traffic and requires human interaction from a user other than the attacker, so the attack vector is not fully remote. The vulnerability is not listed in the CISA KEV catalog. An attacker who successfully abuses the flaw could gain unauthorized data modification, read access to sensitive data, and cause a partial service disruption, but would need a legitimate user to participate in the exploitation.

Generated by OpenCVE AI on April 22, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle patch or upgrade to a version that is not affected by this vulnerability.
  • Restrict HTTP access to the IDM Authentication interface to trusted IP addresses or networks using firewall or ACL rules.
  • Enable logging and monitor for suspicious activity on the IDM Authentication endpoint to detect potential exploitation attempts.

Generated by OpenCVE AI on April 22, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Enables Unauthorized Data Access and Partial Denial of Service in Oracle Life Sciences InForm
Weaknesses CWE-284

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authentication). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Life Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Life Sciences InForm accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Life Sciences InForm. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle life Sciences Inform
CPEs cpe:2.3:a:oracle:life_sciences_inform:7.0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:life_sciences_inform:7.0.1.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle life Sciences Inform
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Life Sciences Inform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-04-21T20:35:41.755Z

Reserved: 2026-03-26T19:48:45.682Z

Link: CVE-2026-34323

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-21T21:16:37.937

Modified: 2026-04-21T21:16:37.937

Link: CVE-2026-34323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T05:00:09Z

Weaknesses