CVE-2025-21528
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-21528 is a vulnerability affecting the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering, specifically versions 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0, and 23.12.1.0-23.12.10.0. This issue is classified as easily exploitable and allows unauthenticated attackers with network access to compromise the system via HTTP. Successful attacks necessitate human interaction from a targeted individual. Potential consequences include unauthorized modification of some Primavera P6 Enterprise Project Portfolio Management data, with integrity impacts assessed at a base score of 4.3. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Primavera P6 Enterprise Project Portfolio Management
Affected Vendors
- Oracle Corp