Unauthorized Access Vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management
CVE-2018-2963

4.3MEDIUM

What is CVE-2018-2963?

A vulnerability in the Web Access component of Oracle's Primavera P6 Enterprise Project Portfolio Management allows a low-privileged attacker with network access via HTTP to gain unauthorized read access to sensitive data. Affected versions include 8.4, 15.x, and 16.x. Successful exploitation can compromise the confidentiality of accessible data within the Primavera P6 system, posing a risk to organizations relying on this essential project management tool.

Affected Version(s)

Primavera P6 Enterprise Project Portfolio Management 8.4

Primavera P6 Enterprise Project Portfolio Management 15.x

Primavera P6 Enterprise Project Portfolio Management 16.x

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.