CVE-2026-21997
Received Received - Intake
Unauthorized Data Modification Vulnerability in Oracle Empirica Signal

Publication date: 2026-04-21

Last updated on: 2026-05-01

Assigner: Oracle

Description
Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica Signal. While the vulnerability is in Oracle Life Sciences Empirica Signal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Life Sciences Empirica Signal accessible data as well as unauthorized read access to a subset of Oracle Life Sciences Empirica Signal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-21
Last Modified
2026-05-01
Generated
2026-05-07
AI Q&A
2026-04-22
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
oracle life_sciences_empirica_signal From 9.2.1 (inc) to 9.2.3 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Oracle Life Sciences Empirica Signal product, specifically in versions 9.2.1 to 9.2.3. It allows a low privileged attacker with network access via HTTP to exploit the system easily. The attacker can compromise the product by gaining unauthorized abilities to create, delete, or modify critical data or any data accessible within Oracle Life Sciences Empirica Signal. Additionally, the attacker can read some subset of the accessible data without authorization.


How can this vulnerability impact me? :

The impact of this vulnerability includes unauthorized creation, deletion, or modification of critical data, which can severely affect the integrity of the system. There is also unauthorized read access to some data, which compromises confidentiality. Because the vulnerability allows such significant unauthorized access, it can lead to data breaches, loss of data integrity, and potentially affect other related products due to scope change.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows unauthorized creation, deletion, modification, and read access to critical data within Oracle Life Sciences Empirica Signal. Such unauthorized access and data manipulation could lead to non-compliance with data protection standards and regulations like GDPR and HIPAA, which require strict controls over data confidentiality, integrity, and access.

Specifically, the confidentiality and integrity impacts indicated by the CVSS score (8.5) suggest that sensitive data could be exposed or altered without authorization, potentially violating regulatory requirements for protecting personal and health information.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart