Web Access Vulnerability in Primavera P6 Project Management by Oracle
CVE-2018-3241

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

A security issue exists in the Web Access component of Primavera P6 Enterprise Project Portfolio Management that allows an unauthenticated attacker with network access to potentially manipulate data. This vulnerability requires human interaction from a victim for exploitation. Attackers can gain unauthorized access to update, insert, or delete data and may also read sensitive information that should be protected. This could lead to significant implications for data integrity and confidentiality not just within Primavera P6, but also across other connected systems.

Affected Version(s)

Primavera P6 Enterprise Project Portfolio Management 8.4

Primavera P6 Enterprise Project Portfolio Management 15.1

Primavera P6 Enterprise Project Portfolio Management 15.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.