CVE-2020-14617

4 documents4 sources
Severity
5.7MEDIUM
EPSS
0.6%
top 30.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App). Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and 19.12; Mobile App: Prior to 20.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unaut

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages2 packages

NVDoracle/primavera_unifier17.717.12+5
CVEListV5oracle_corporation/primavera_unifier5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4rg7-5qhh-6v5f: Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App)2022-05-24
CVEList
CVE-2020-14617: Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App)2020-07-15

📋Vendor Advisories

1
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Platform, Mobile App — CVE-2020-146172020-07-15
CVE-2020-14617 (MEDIUM CVSS 5.7) | Vulnerability in the Primavera Unif | cvebase.io