Executive brief
A vulnerability in the Team Member subcomponent of Oracle Primavera P6 EPPM allows an attacker to gain unauthorized access to project management data. Primavera P6 is used by organizations to manage large-scale project portfolios, and an exploit could lead to the unauthorized viewing, modification, or deletion of sensitive project schedules and corporate data. This could result in significant operational disruption and the loss of proprietary business information.
Technical details
This vulnerability affects the Team Member subcomponent of Oracle Primavera P6 Enterprise Project Portfolio Management (EPPM). It is classified as an improper access control issue that is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to compromise the confidentiality and integrity of all accessible data within the application, including the ability to create, delete, or modify critical project records. The vulnerability does not impact system availability but provides full access to the application's data layer. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle Primavera P6 Enterprise Project Portfolio Management 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, 16.2
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published