Security restrictions bypass in Primavera P6 Enterprise Project Portfolio Management - CVE-2019-2512

 

Security restrictions bypass in Primavera P6 Enterprise Project Portfolio Management - CVE-2019-2512

Published: January 17, 2019


Vulnerability identifier: #VU17054
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2512
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to insufficient input validation. A remote attacker can trick the victim into processing specially crafted input and bypass security restrictions to read and modify arbitrary system files.

Affected software

Primavera P6 Enterprise Project Portfolio Management

How to mitigate CVE-2019-2512

Install update from vendor's website.


External References

Related Security Bulletins