CVE-2025-21526
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-21526 is a vulnerability affecting the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering, specifically the Web Access component. Affected versions include 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0, and 23.12.1.0-23.12.10.0. this issue is classified as easily exploitable and allows a low-privileged attacker with network access to compromise the system. Successful attacks require human interaction and can grant unauthorized access to update, insert or delete data, as well as unauthorized read access to a subset of data. Impacted data may belong to Primavera P6 Enterprise Project Portfolio Management, but additional products may also be affected. The Base Score of this vulnerability according to the Common Vulnerability Scoring System (CVSS) version 3.1 is 5.4, with both confidentiality and integrity impacts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Primavera P6 Enterprise Project Portfolio Management
Affected Vendors
- Oracle Corp