OSA-36725517
Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Install (Apache Commons IO)). The supported version that is affected is 4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences Information Manager. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).
Risk Scores
Timeline
- Jan 20, 2026 CVE Published