Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences InForm. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Life Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Life Sciences InForm accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
CVE-2026-34324 is an unauthenticated network vulnerability in Oracle Life Sciences InForm versions 7.0.1.0 and 7.0.1.1 that allows attackers to read, modify, insert, or delete sensitive data via HTTP. The vulnerability requires no user interaction and can be exploited remotely with low complexity.
ثغرة في Oracle Life Sciences InForm تسمح للمهاجمين غير المصرحين بالوصول إلى البيانات الحساسة عبر HTTP دون الحاجة للمصادقة. يمكن للمهاجمين قراءة وتعديل وحذف البيانات المتاحة في التطبيق مما يؤثر على سرية وسلامة البيانات.
This vulnerability affects Oracle Life Sciences InForm versions 7.0.1.0 and 7.0.1.1, allowing unauthenticated remote attackers to compromise data confidentiality and integrity through HTTP access. Organizations using affected versions face risks of unauthorized data access and modification without authentication requirements.
Immediately upgrade Oracle Life Sciences InForm to versions beyond 7.0.1.1. Apply all available security patches from Oracle. Implement network segmentation to restrict HTTP access to the application. Deploy Web Application Firewall (WAF) rules to monitor and block suspicious requests. Conduct security audit of data accessed during the vulnerability window.
قم بترقية Oracle Life Sciences InForm فوراً إلى إصدارات أحدث من 7.0.1.1. طبق جميع التصحيحات الأمنية المتاحة من Oracle. طبق تقسيم الشبكة لتقييد الوصول عبر HTTP. نشر قواعد جدار الحماية لتطبيقات الويب لمراقبة الطلبات المريبة. أجرِ تدقيق أمني للبيانات المُوصول إليها خلال فترة الثغرة.