4.3
CVE-2022-21243
- EPSS 0.31%
- Published 19.01.2022 12:15:10
- Last modified 21.11.2024 06:44:11
- Source secalert_us@oracle.com
- Teams watchlist Login
- Open Login
Vulnerability in the Primavera Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 18.0.0.0-18.0.3.0, 19.0.0.0-19.0.1.2, 20.0.0.0 and 20.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Portfolio Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Portfolio Management. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Primavera Portfolio Management Version >= 18.0.0.0 <= 18.0.3.0
Oracle ≫ Primavera Portfolio Management Version >= 19.0.0.0 <= 19.0.1.2
Oracle ≫ Primavera Portfolio Management Version20.0.0.0
Oracle ≫ Primavera Portfolio Management Version20.0.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.31% | 0.514 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
secalert_us@oracle.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|