Unauthorized Access Vulnerability in Primavera Portfolio Management by Oracle
CVE-2022-21244
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 19 January 2022
What is CVE-2022-21244?
A vulnerability exists in Oracle's Primavera Portfolio Management Web Access component that allows unauthenticated attackers with network access to exploit the system. While successful exploitation requires human interaction from another user, it enables attackers to perform unauthorized operations such as updates, inserts, or deletions of accessible data. This impacts the integrity of the application's data and emphasizes the importance of implementing security practices to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Primavera Portfolio Management 18.0.0.0-18.0.3.0
Primavera Portfolio Management 19.0.0.0-19.0.1.2
Primavera Portfolio Management 20.0.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved