Impact
The IDM Authentication component in Oracle Life Sciences InForm versions 7.0.1.0 and 7.0.1.1 contains a flaw that allows an unauthenticated attacker who can reach the system over HTTP to perform unauthorized update, insert or delete operations on data and read data that should be protected, as well as to cause a partial denial of service. The flaw results in modest confidentiality, integrity and availability impact as reflected in a CVSS 3.1 base score of 6.3 (C:L/I:L/A:L).
Affected Systems
Affected systems include Oracle Corporation’s Life Sciences InForm application, specifically versions 7.0.1.0 and 7.0.1.1.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity, and because the EPSS is not available, the likelihood of exploitation is unclear. The vulnerability must be exploited through HTTP traffic and requires human interaction from a user other than the attacker, so the attack vector is not fully remote. The vulnerability is not listed in the CISA KEV catalog. An attacker who successfully abuses the flaw could gain unauthorized data modification, read access to sensitive data, and cause a partial service disruption, but would need a legitimate user to participate in the exploitation.
OpenCVE Enrichment