Unauthorized Access Vulnerability in Primavera Portfolio Management by Oracle
CVE-2022-21269

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

A vulnerability in the Primavera Portfolio Management product of Oracle allows an unauthenticated attacker with network access via HTTP to compromise the application. This issue affects multiple supported versions and requires human interaction from a user who is not the attacker to exploit it successfully. Once exploited, it can lead to unauthorized update, insert, or delete actions on accessible data within Primavera, as well as unauthorized read access to a subset of this data. Such vulnerabilities can significantly impact the integrity and confidentiality of the system.

Affected Version(s)

Primavera Portfolio Management 18.0.0.0-18.0.3.0

Primavera Portfolio Management 19.0.0.0-19.0.1.2

Primavera Portfolio Management 20.0.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.