Vulnerability in Primavera Gateway of Oracle Construction and Engineering
CVE-2023-21888
5.4MEDIUM
Summary
A vulnerability in the Primavera Gateway product from Oracle’s Construction and Engineering division could allow low-privileged attackers with network access to exploit the system via HTTP. The issue affects specific versions of the software and requires human interaction to initiate a successful attack. If exploited, the vulnerability may enable unauthorized updates, deletions, and reading of accessible data, thus compromising the integrity and confidentiality of Primavera Gateway data. Attackers might also gain the potential to affect additional connected products.
Affected Version(s)
Primavera Gateway 18.8.0-18.8.15
Primavera Gateway 19.12.0-19.12.15
Primavera Gateway 20.12.0-20.12.10
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved