Web Access Vulnerability in Primavera Portfolio Management by Oracle
CVE-2022-21281
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 19 January 2022
What is CVE-2022-21281?
A vulnerability exists in the Web Access component of Oracle's Primavera Portfolio Management that allows attackers with high privileges and network access to exploit the system. The vulnerability requires user interaction from an external party and could lead to unauthorized alterations, including insertions, updates, and deletions of accessible data. Additionally, it poses risks of unauthorized read access to specific subsets of Primavera Portfolio Management data, impacting overall data confidentiality and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Primavera Portfolio Management 18.0.0.0-18.0.3.0
Primavera Portfolio Management 19.0.0.0-19.0.1.2
Primavera Portfolio Management 20.0.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved