Vulnerability in Primavera Unifier Component of Oracle Primavera Products Suite
CVE-2017-10149
4.8MEDIUM
Summary
A vulnerability in the Primavera Unifier component of the Oracle Primavera Products Suite allows high privileged attackers with network access via HTTP to exploit the system. This easily exploitable weakness requires human interaction from a third party, making targeted attacks more feasible. While primarily affecting Primavera Unifier, successful exploitation can lead to unauthorized updates, insertions, or deletions of data, as well as unauthorized reading of certain Primavera Unifier accessible information. As such, it poses notable risks to users and organizations relying on the affected versions.
Affected Version(s)
Primavera Unifier 9.13
Primavera Unifier 9.14
Primavera Unifier 10.1
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved