Unauthorized Access Vulnerability in Oracle Primavera Unifier
CVE-2017-3501

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A vulnerability in the Primavera Unifier component of Oracle's Primavera Products Suite allows an unauthenticated attacker with network access via HTTP to compromise the system. This flaw necessitates human interaction from an external party to succeed in an attack. Although the primary vulnerability resides within Primavera Unifier, any successful exploitation can have significant repercussions on other interconnected products. Attackers may gain unauthorized access to sensitive data and perform potentially harmful operations, such as updating, inserting, or deleting data, leading to data integrity and confidentiality concerns.

Affected Version(s)

Primavera Unifier 9.13

Primavera Unifier 9.14

Primavera Unifier 10.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.