Oracle Health Sciences Inform vulnerabilities
8 known vulnerabilities affecting oracle/health_sciences_inform.
Total CVEs
8
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2023-21923HIGHCVSS 8.3fixed in 6.3.1.3v7.0.0.02023-04-18
CVE-2023-21923 [HIGH] CWE-284 CVE-2023-21923: Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (c
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks
nvd
CVE-2023-21925MEDIUMCVSS 5.3fixed in 6.3.1.3v7.0.0.02023-04-18
CVE-2023-21925 [MEDIUM] CWE-400 CVE-2023-21925: Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (c
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful atta
nvd
CVE-2023-21921MEDIUMCVSS 5.4fixed in 6.3.1.3v7.0.0.02023-04-18
CVE-2023-21921 [MEDIUM] CVE-2023-21921: Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (c
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of th
nvd
CVE-2023-21922MEDIUMCVSS 6.8fixed in 6.3.1.3v7.0.0.02023-04-18
CVE-2023-21922 [MEDIUM] CWE-284 CVE-2023-21922: Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (c
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful at
nvd
CVE-2023-21926MEDIUMCVSS 5.5fixed in 6.3.1.3v7.0.0.02023-04-18
CVE-2023-21926 [MEDIUM] CVE-2023-21926: Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (c
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Health Sciences InForm executes to compromise Oracl
nvd
CVE-2023-21924MEDIUMCVSS 5.9fixed in 6.3.1.3v7.0.0.02023-04-18
CVE-2023-21924 [MEDIUM] CVE-2023-21924: Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (c
Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks requ
nvd
CVE-2021-45105MEDIUMCVSS 5.9v6.2.1.1v6.3.2.1+1 more2021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2020-11023MEDIUMCVSS 6.1KEVPoCv6.3.02020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd