CVE-2025-61885Medium· 4.3▾ SunlitVulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences InForm. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Life Sciences InForm accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
life_sciences_inform = 7.0.1.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62287Medium· 6.1Vulnerability in the Oracle Life Sciences InForm product of Oracle Health Sciences Applications (component: Web Server)
CVE-2026-87225High· 7.1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2026-87221High· 7.5Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2026-87209High· 7.1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2025-30758Medium· 5.3Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface)
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header