Vulnerability in Primavera P6 Enterprise Project Portfolio Management by Oracle
CVE-2018-3281

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

This vulnerability in Oracle's Primavera P6 Enterprise Project Portfolio Management enables unauthenticated attackers to gain unauthorized access through HTTP. Although successful exploits necessitate human interaction, they can lead to potentially severe implications for accessible project data, including unauthorized updates, deletions, and read operations. This vulnerability affects specific versions of the Primavera P6 software, posing a risk not only to the application itself but also potentially impacting other integrated tools within the suite.

Affected Version(s)

Primavera P6 Enterprise Project Portfolio Management 8.4

Primavera P6 Enterprise Project Portfolio Management 15.1

Primavera P6 Enterprise Project Portfolio Management 15.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.