CVE-2025-21526

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21526 is a vulnerability affecting the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering, specifically the Web Access component. Affected versions include 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0, and 23.12.1.0-23.12.10.0. this issue is classified as easily exploitable and allows a low-privileged attacker with network access to compromise the system. Successful attacks require human interaction and can grant unauthorized access to update, insert or delete data, as well as unauthorized read access to a subset of data. Impacted data may belong to Primavera P6 Enterprise Project Portfolio Management, but additional products may also be affected. The Base Score of this vulnerability according to the Common Vulnerability Scoring System (CVSS) version 3.1 is 5.4, with both confidentiality and integrity impacts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Primavera P6 Enterprise Project Portfolio Management

Affected Vendors

  • Oracle Corp