Vulnerability in Primavera P6 Enterprise Project Portfolio Management by Oracle
CVE-2025-21558

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2025

Summary

A vulnerability has been identified in Oracle's Primavera P6 Enterprise Project Portfolio Management, specifically within the Web Access component. This flaw allows low-privileged attackers with network access via HTTP to exploit the system, requiring human interaction from a third party. Although primarily affecting Primavera P6, successful exploitation could have broader implications for associated products. Attackers may gain unauthorized capabilities to update, insert, delete, or read sensitive data within the system, compromising both confidentiality and integrity of the accessible data.

Affected Version(s)

Primavera P6 Enterprise Project Portfolio Management 20.12.1.0 <= 20.12.21.5

Primavera P6 Enterprise Project Portfolio Management 21.12.1.0 <= 21.12.20.0

Primavera P6 Enterprise Project Portfolio Management 22.12.1.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.