CVE-2025-21558
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-21558 is a vulnerability affecting the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering, specifically the Web Access component. Affected versions include 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, and 22.12.1.0. This issue enables a low-privileged attacker with network access to compromise the system via HTTP. While exploitation requires human interaction, successful attacks may lead to unauthorized data access, including both update, insert, delete, and read access. The Base Score is 5.4, with Confidentiality and Integrity impacts. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Primavera P6 Enterprise Project Portfolio Management
Affected Vendors
- Oracle Corp