Oracle Primavera is prone to a remote vulnerability in Primavera P6 Enterprise Project Portfolio Management.
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0558
The original article can be found at: http://www.securityfocus.com/bid/53056
Vulnerable Systems:
* Oracle Primavera P6 Enterprise Project Portfolio Management 6.2.1
* Oracle Primavera P6 Enterprise Project Portfolio Management 8.2
* Oracle Primavera P6 Enterprise Project Portfolio Management 8.1
* Oracle Primavera P6 Enterprise Project Portfolio Management 8.0
* Oracle Primavera P6 Enterprise Project Portfolio Management 7.0.1.0
* Oracle Primavera P6 Enterprise Project Portfolio Management 7.0
* Oracle Primavera P6 Enterprise Project Portfolio Management 6.21.3.0
* Oracle Primavera P6 Enterprise Project Portfolio Management 6.1
The vulnerability can be exploited over the 'HTTP' protocol. The 'Web application' sub component is affected.
This vulnerability affects the following supported versions:
6.2.1, 8.0, 8.1, 8.2
Vendor Status:
Oracle as issued an update for this vulnerablity
Patch Availability:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
CVE Information:
CVE-2012-0558
Disclosure Timeline:
2012-April-17 Rev 1. Initial Release
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by