Security restrictions bypass in Primavera P6 Enterprise Project Portfolio Management - CVE-2019-2512
Published: January 17, 2019
Vulnerability identifier: #VU17054
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2512
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to insufficient input validation. A remote attacker can trick the victim into processing specially crafted input and bypass security restrictions to read and modify arbitrary system files.
The weakness exists due to insufficient input validation. A remote attacker can trick the victim into processing specially crafted input and bypass security restrictions to read and modify arbitrary system files.
Affected software
Primavera P6 Enterprise Project Portfolio Management
How to mitigate CVE-2019-2512
Install update from vendor's website.