CVE-2025-21528

Severity
4.3MEDIUM
EPSS
0.1%
top 64.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21

Description

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0 and 23.12.1.0-23.12.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person o

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
CVE-2025-21528: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access)2025-01-21
GHSA
GHSA-fr8h-82qf-8xg7: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access)2025-01-21

📋Vendor Advisories

2
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Web Access — CVE-2025-215282025-01-15
Microsoft
A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file.2023-08-08