CVE-2025-21558

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21558 is a vulnerability affecting the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering, specifically the Web Access component. Affected versions include 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, and 22.12.1.0. This issue enables a low-privileged attacker with network access to compromise the system via HTTP. While exploitation requires human interaction, successful attacks may lead to unauthorized data access, including both update, insert, delete, and read access. The Base Score is 5.4, with Confidentiality and Integrity impacts. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Primavera P6 Enterprise Project Portfolio Management

Affected Vendors

  • Oracle Corp