CVE-2025-21558Incorrect Authorization in Corporation Primavera P6 Enterprise Project Portfolio Management

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 67.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21

Description

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0 and 22.12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks require human interaction from a person other than the attacker and while t

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-35v7-q7c2-qg94: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access)2025-01-21
CVEList
CVE-2025-21558: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access)2025-01-21

📋Vendor Advisories

1
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Web Access — CVE-2025-215582025-01-15
CVE-2025-21558 — Incorrect Authorization | cvebase