Oracle Primavera P6 Enterprise Project Portfolio Management vulnerabilities
63 known vulnerabilities affecting oracle/primavera_p6_enterprise_project_portfolio_management.
Total CVEs
63
CISA KEV
0
Public exploits
4
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH9MEDIUM45
Vulnerabilities
Page 1 of 4
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomware≥ 19.12.0.0, ≤ 19.12.18.0≥ 20.12.0.0, ≤ 20.12.12.0+1 more2021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-44832P1MEDIUMCVSS 6.6ExploitedRansomware≥ 19.12.0, ≤ 19.12.18.0≥ 20.12.0.0, ≤ 20.12.12.0+2 more2021-12-28
CVE-2021-44832 [MEDIUM] CWE-20 CVE-2021-44832: Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) a
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java
nvd
CVE-2012-3137P2MEDIUMCVSS 6.4PoCv8.2v8.3+1 more2012-09-21
CVE-2012-3137 [MEDIUM] CWE-287 CVE-2012-3137: The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtain the session key and salt for arbitrary users, which leaks information about the cryptographic hash and makes it easier to conduct brute force password guessing attacks, aka "stealth password cracking vu
nvd
CVE-2018-14718P2CRITICALCVSS 9.8≥ 17.7, ≤ 17.12v15.1+4 more2019-01-02
CVE-2018-14718 [CRITICAL] CWE-502 CVE-2018-14718: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
nvd
CVE-2018-14719P2CRITICALCVSS 9.8≥ 17.7, ≤ 17.12v15.1+4 more2019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2017-3324P2CRITICALCVSS 10.0v8.2v8.3+5 more2017-01-27
CVE-2017-3324 [CRITICAL] CVE-2017-3324: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primav
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterpri
nvd
CVE-2016-0635P3HIGHCVSS 8.8v8.2v8.3+4 more2016-07-21
CVE-2016-0635 [HIGH] CVE-2016-0635: Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manage
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.
nvd
CVE-2017-3503P3CRITICALCVSS 9.9v8.3v8.4+4 more2017-04-24
CVE-2017-3503 [CRITICAL] CVE-2017-3503: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primav
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access (Apache Commons BeanUtils)). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromis
nvd
CVE-2017-10046P3MEDIUMCVSS 5.4PoCv8.3v8.4+3 more2017-08-08
CVE-2017-10046 [MEDIUM] CWE-269 CVE-2017-10046: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primav
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2 and 16.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise P
nvd
CVE-2020-10683P3CRITICALCVSS 9.8≥ 16.1.0.0, ≤ 16.2.20.1≥ 17.1.0.0, ≤ 17.12.17.1+2 more2020-05-01
CVE-2020-10683 [CRITICAL] CWE-611 CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, whi
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
nvd
CVE-2018-19360P3CRITICALCVSS 9.8≥ 17.7, ≤ 17.12v15.1+4 more2019-01-02
CVE-2018-19360 [CRITICAL] CWE-502 CVE-2018-19360: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
nvd
CVE-2018-19361P3CRITICALCVSS 9.8≥ 17.7, ≤ 17.12v15.1+4 more2019-01-02
CVE-2018-19361 [CRITICAL] CWE-502 CVE-2018-19361: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
nvd
CVE-2018-19362P3CRITICALCVSS 9.8≥ 17.7, ≤ 17.12v15.1+4 more2019-01-02
CVE-2018-19362 [CRITICAL] CWE-502 CVE-2018-19362: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
nvd
CVE-2024-21095P3HIGHCVSS 8.2≥ 19.12.0, ≤ 19.12.22≥ 20.12.0, ≤ 20.12.21+3 more2024-04-16
CVE-2024-21095 [HIGH] CWE-200 CVE-2024-21095: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construc
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 19.12.0-19.12.22, 20.12.0-20.12.21, 21.12.0-21.12.18, 22.12.0-22.12.12 and 23.12.0-23.12.2. Easily exploitable vulnerability allows unauthenticated attacker with netw
nvd
CVE-2019-3020P3CRITICALCVSS 9.3≥ 15.1.0, ≤ 15.2.18≥ 16.1.0, ≤ 16.2.18+2 more2019-10-16
CVE-2019-3020 [CRITICAL] CVE-2019-3020: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construc
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 15.1.0-15.2.18, 16.1.0-16.2.18, 17.1.0-17.12.14 and 18.1.0-18.8.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to comprom
nvd
CVE-2018-5407P4MEDIUMCVSS 4.7PoC≥ 17.7, ≤ 17.12v8.4+5 more2018-11-15
CVE-2018-5407 [MEDIUM] CWE-200 CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerab
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
nvd
CVE-2018-1000632P3HIGHCVSS 7.5≥ 16.1.0.0, ≤ 16.2.20.1≥ 17.1.0.0, ≤ 17.12.17.1+2 more2018-08-20
CVE-2018-1000632 [HIGH] CWE-91 CVE-2018-1000632: dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Elemen
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability app
nvd
CVE-2021-2351P3HIGHCVSS 7.5≥ 17.12.0.0, ≤ 17.12.20≥ 18.8.0.0, ≤ 18.8.24+2 more2021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2017-3263P3HIGHCVSS 8.1v8.2v8.3+5 more2017-01-27
CVE-2017-3263 [HIGH] CVE-2017-3263: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primav
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Team Member). Supported versions that are affected are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise P
nvd
CVE-2017-3583P3HIGHCVSS 8.1v8.3v8.4+4 more2017-04-24
CVE-2017-3583 [HIGH] CVE-2017-3583: Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primav
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Proj
nvd
1 / 4Next →