Web Access Vulnerability in Oracle Primavera Unifier
CVE-2018-3148

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

A vulnerability exists in the Web Access component of Oracle Primavera Unifier, allowing unauthorized access to sensitive data. An unauthenticated attacker with network access can compromise the application by leveraging human interaction to execute attacks. This vulnerability can lead to unauthorized updates, inserts, or deletions of Primavera Unifier data, as well as unauthorized reading of accessible data. The affected versions span from 15.1 to 18.8, emphasizing the need for immediate attention to mitigate potential risks.

Affected Version(s)

Primavera Unifier 15.1

Primavera Unifier 15.2

Primavera Unifier 16.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.