Vulnerability in Primavera P6 Enterprise Project Portfolio Management by Oracle
CVE-2025-21558
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 January 2025
Summary
A vulnerability has been identified in Oracle's Primavera P6 Enterprise Project Portfolio Management, specifically within the Web Access component. This flaw allows low-privileged attackers with network access via HTTP to exploit the system, requiring human interaction from a third party. Although primarily affecting Primavera P6, successful exploitation could have broader implications for associated products. Attackers may gain unauthorized capabilities to update, insert, delete, or read sensitive data within the system, compromising both confidentiality and integrity of the accessible data.
Affected Version(s)
Primavera P6 Enterprise Project Portfolio Management 20.12.1.0 <= 20.12.21.5
Primavera P6 Enterprise Project Portfolio Management 21.12.1.0 <= 21.12.20.0
Primavera P6 Enterprise Project Portfolio Management 22.12.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved