Unauthorized Access Vulnerability in Oracle Primavera Unifier Product
CVE-2020-14617
5.7MEDIUM
Summary
A vulnerability exists in the Primavera Unifier product of Oracle Construction and Engineering that permits low-privilege attackers with network access via HTTPS to compromise the system. Affected versions include 16.1, 16.2, 17.7 to 17.12, 18.8, and 19.12, along with the Mobile App prior to version 20.6. This vulnerability necessitates human interaction from an individual other than the attacker, but successful exploits can enable unauthorized access to critical data or comprehensive data retrieval within Primavera Unifier.
Affected Version(s)
Primavera Unifier 16.1
Primavera Unifier 16.2
Primavera Unifier 17.7-17.12
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved