Unauthorized Access Vulnerability in Primavera Portfolio Management by Oracle
CVE-2022-21244

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

A vulnerability exists in Oracle's Primavera Portfolio Management Web Access component that allows unauthenticated attackers with network access to exploit the system. While successful exploitation requires human interaction from another user, it enables attackers to perform unauthorized operations such as updates, inserts, or deletions of accessible data. This impacts the integrity of the application's data and emphasizes the importance of implementing security practices to mitigate potential risks.

Affected Version(s)

Primavera Portfolio Management 18.0.0.0-18.0.3.0

Primavera Portfolio Management 19.0.0.0-19.0.1.2

Primavera Portfolio Management 20.0.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.