CVE-2025-21526

Severity
5.4MEDIUM
EPSS
0.2%
top 64.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21

Description

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0 and 23.12.1.0-23.12.10.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person ot

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-qjjp-gpj3-qwwr: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access)2025-01-21
CVEList
CVE-2025-21526: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access)2025-01-21

📋Vendor Advisories

1
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Web Access — CVE-2025-215262025-01-15