Web Access Vulnerability in Oracle Primavera Portfolio Management
CVE-2022-21243

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

A vulnerability in Oracle Primavera Portfolio Management's Web Access component allows a low-privileged attacker with network access via HTTP to exploit the system. This exploitation can lead to unauthorized actions that compromise the availability of the Primavera service, potentially resulting in partial denial of service (DOS). Organizations using affected versions should prioritize remediation to secure their environment from potential risks.

Affected Version(s)

Primavera Portfolio Management 18.0.0.0-18.0.3.0

Primavera Portfolio Management 19.0.0.0-19.0.1.2

Primavera Portfolio Management 20.0.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.