Low Privilege Vulnerability in Primavera Portfolio Management by Oracle
CVE-2022-21242
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 January 2022
Summary
A vulnerability exists in the Primavera Portfolio Management product from Oracle's Construction and Engineering division, specifically affecting its Web Access component. The supported versions at risk range from 18.0.0.0 to 20.0.0.1. This vulnerability is easily exploitable by low-privileged attackers with network access via HTTP, requiring some level of human interaction from non-attacking persons. Although primarily affecting Primavera Portfolio Management, the attack could also influence other associated products. Successful exploitation could permit unauthorized updates, insertions, or deletions of accessible data, and unauthorized read access to a portion of Primavera Portfolio Management's data.
Affected Version(s)
Primavera Portfolio Management 18.0.0.0-18.0.3.0
Primavera Portfolio Management 19.0.0.0-19.0.1.2
Primavera Portfolio Management 20.0.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved