Low Privilege Vulnerability in Primavera Portfolio Management by Oracle
CVE-2022-21242

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

A vulnerability exists in the Primavera Portfolio Management product from Oracle's Construction and Engineering division, specifically affecting its Web Access component. The supported versions at risk range from 18.0.0.0 to 20.0.0.1. This vulnerability is easily exploitable by low-privileged attackers with network access via HTTP, requiring some level of human interaction from non-attacking persons. Although primarily affecting Primavera Portfolio Management, the attack could also influence other associated products. Successful exploitation could permit unauthorized updates, insertions, or deletions of accessible data, and unauthorized read access to a portion of Primavera Portfolio Management's data.

Affected Version(s)

Primavera Portfolio Management 18.0.0.0-18.0.3.0

Primavera Portfolio Management 19.0.0.0-19.0.1.2

Primavera Portfolio Management 20.0.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.