Vulnerability in Primavera P6 Project Management by Oracle
CVE-2020-2706

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

An easily exploitable vulnerability exists in Oracle's Primavera P6 Enterprise Project Portfolio Management that allows a low privileged attacker with network access via HTTP to compromise the system. Successful exploitation may require human interaction and can lead to unauthorized read, update, insert, or delete access to data within Primavera P6. While primarily affecting Primavera P6, the implications of successful attacks can extend to other interconnected systems and applications.

Affected Version(s)

Primavera P6 Enterprise Project Portfolio Management 16.2.0.0 - 16.2.19.3

Primavera P6 Enterprise Project Portfolio Management 17.12.0.0 - 17.12.17.0

Primavera P6 Enterprise Project Portfolio Management 18.8.0.0 - 18.8.18.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.