Unauthorized Data Manipulation Vulnerability in Oracle Primavera Portfolio Management
CVE-2020-14566

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists in the Web Access component of Oracle's Primavera Portfolio Management, which can be exploited by unauthenticated attackers with network access via HTTP. The vulnerability allows these attackers to gain unauthorized update, insert, or delete access to certain data within Primavera Portfolio Management. While successful exploitation necessitates some level of human interaction from an outside party, the ease of the attack makes it a significant concern for organizations utilizing these versions.

Affected Version(s)

Primavera Portfolio Management 16.1.0.0-16.1.5.1

Primavera Portfolio Management 18.0.0.0-18.0.2.0

Primavera Portfolio Management 19.0.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.