Oracle Primavera P6 EPPM Web Access Vulnerability Allowing Unauthorized Data Access and Modification

Vulnerability

A vulnerability has been identified in the Web Access component of Oracle Primavera P6 Enterprise Project Portfolio Management, affecting versions 20.12.1.0 through 20.12.21.5, 21.12.1.0 through 21.12.20.0, 22.12.1.0 through 22.12.16.0, and 23.12.1.0 through 23.12.10.0. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Primavera P6 EPPM. Exploitation requires human interaction from a third party. While the vulnerability resides within Primavera P6 EPPM, successful attacks could significantly impact other products, leading to a scope change. Exploiting this vulnerability could result in unauthorized read, update, insert, or delete access to certain accessible data within Primavera P6 EPPM.

Impact

Exploitation of this vulnerability could lead to unauthorized read, update, insert, or delete access to some of the data accessible within Primavera P6 EPPM.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.3
exploitability
5.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.