Web Access Vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management
CVE-2025-21526
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 January 2025
Summary
A vulnerability exists in Oracle's Primavera P6 Enterprise Project Portfolio Management affecting specific versions of the Web Access component. This weakness allows low-privileged attackers with network access to compromise the application, necessitating human interaction for exploitation. Resulting attacks can lead to unauthorized updates, deletions, or access to sensitive data within Primavera P6. Additionally, successful exploitation may extend beyond the primary product, affecting other related systems. It is crucial to apply recommended security patches to mitigate risks associated with this vulnerability.
Affected Version(s)
Primavera P6 Enterprise Project Portfolio Management 20.12.1.0 <= 20.12.21.5
Primavera P6 Enterprise Project Portfolio Management 21.12.1.0 <= 21.12.20.0
Primavera P6 Enterprise Project Portfolio Management 22.12.1.0 <= 22.12.16.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved