Vulnerability in Oracle Primavera Unifier Component
CVE-2018-2967

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

A vulnerability exists in the Primavera Unifier component of Oracle's Construction and Engineering Suite, affecting versions 16.x, 17.x, and 18.x. This easily exploitable access control flaw requires physical access and can lead to unauthorized entry into Primavera Unifier. Exploitation of this vulnerability poses a significant risk, as it may lead to unauthorized access to critical data or potentially all data that is accessible through Primavera Unifier, substantially compromising data integrity and confidentiality.

Affected Version(s)

Primavera Unifier 16.x

Primavera Unifier 17.x

Primavera Unifier 18.x

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.