Unauthorized Data Manipulation Vulnerability in Oracle Primavera Portfolio Management
CVE-2020-14566
4.3MEDIUM
Summary
A vulnerability exists in the Web Access component of Oracle's Primavera Portfolio Management, which can be exploited by unauthenticated attackers with network access via HTTP. The vulnerability allows these attackers to gain unauthorized update, insert, or delete access to certain data within Primavera Portfolio Management. While successful exploitation necessitates some level of human interaction from an outside party, the ease of the attack makes it a significant concern for organizations utilizing these versions.
Affected Version(s)
Primavera Portfolio Management 16.1.0.0-16.1.5.1
Primavera Portfolio Management 18.0.0.0-18.0.2.0
Primavera Portfolio Management 19.0.0.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved