CVE-2025-50061
BaseFortify
Publication date: 2025-07-15
Last updated on: 2025-07-24
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | primavera_p6_enterprise_project_portfolio_management | From 20.12.0 (inc) to 20.12.21 (inc) |
| oracle | primavera_p6_enterprise_project_portfolio_management | From 21.12.0.0 (inc) to 21.12.21.0 (inc) |
| oracle | primavera_p6_enterprise_project_portfolio_management | From 22.12.0 (inc) to 22.12.19 (inc) |
| oracle | primavera_p6_enterprise_project_portfolio_management | From 23.12.0 (inc) to 23.12.13 (inc) |
| oracle | primavera_p6_enterprise_project_portfolio_management | From 24.12.0 (inc) to 24.12.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects the Primavera P6 Enterprise Project Portfolio Management product by Oracle Construction and Engineering, specifically its Web Access component. It allows a low privileged attacker with network access via HTTP to compromise the system. The attack requires human interaction from someone other than the attacker. Successful exploitation can lead to unauthorized reading, updating, inserting, or deleting of some accessible data within Primavera P6. The vulnerability has a CVSS 3.1 base score of 5.4, indicating a moderate severity with impacts on confidentiality and integrity.
How can this vulnerability impact me? :
If exploited, this vulnerability can allow an attacker to gain unauthorized access to some data in Primavera P6, including the ability to read, update, insert, or delete that data. This could lead to data integrity issues, unauthorized data disclosure, and potential disruption of project portfolio management operations.