Unauthorized Access Vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management
CVE-2018-2963
4.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 July 2018
Summary
A vulnerability in the Web Access component of Oracle's Primavera P6 Enterprise Project Portfolio Management allows a low-privileged attacker with network access via HTTP to gain unauthorized read access to sensitive data. Affected versions include 8.4, 15.x, and 16.x. Successful exploitation can compromise the confidentiality of accessible data within the Primavera P6 system, posing a risk to organizations relying on this essential project management tool.
Affected Version(s)
Primavera P6 Enterprise Project Portfolio Management 8.4
Primavera P6 Enterprise Project Portfolio Management 15.x
Primavera P6 Enterprise Project Portfolio Management 16.x
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved