cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2020-14618,https://securityvulnerability.io/vulnerability/CVE-2020-14618,Unauthorized Access Vulnerability in Primavera Unifier Mobile App by Oracle,"A security vulnerability in the Primavera Unifier Mobile App by Oracle could allow unauthenticated attackers with network access via HTTPS to compromise the system. Exploiting this vulnerability requires human interaction from a user, potentially leading to unauthorized access to sensitive data. An attacker may gain complete access to all Primavera Unifier accessible data and perform unauthorized updates, inserts, or deletions. The supported version affected is prior to 20.6, emphasizing the importance of regular updates to mitigate such risks.",Oracle,Primavera Unifier,5.9,MEDIUM,0.002369999885559082,false,,false,false,false,,,false,false,,2020-07-15T17:34:30.000Z,0 CVE-2020-14617,https://securityvulnerability.io/vulnerability/CVE-2020-14617,Unauthorized Access Vulnerability in Oracle Primavera Unifier Product,"A vulnerability exists in the Primavera Unifier product of Oracle Construction and Engineering that permits low-privilege attackers with network access via HTTPS to compromise the system. Affected versions include 16.1, 16.2, 17.7 to 17.12, 18.8, and 19.12, along with the Mobile App prior to version 20.6. This vulnerability necessitates human interaction from an individual other than the attacker, but successful exploits can enable unauthorized access to critical data or comprehensive data retrieval within Primavera Unifier.",Oracle,Primavera Unifier,5.7,MEDIUM,0.0006399999838322401,false,,false,false,false,,,false,false,,2020-07-15T17:34:30.000Z,0 CVE-2018-3148,https://securityvulnerability.io/vulnerability/CVE-2018-3148,,"Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Web Access). Supported versions that are affected are 15.1, 15.2, 16.1, 16.2, 17.1-17.12 and 18.1-18.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",Oracle,Primavera Unifier,6.1,MEDIUM,0.0006900000153109431,false,,false,false,false,,,false,false,,2018-10-17T01:00:00.000Z,0 CVE-2018-2968,https://securityvulnerability.io/vulnerability/CVE-2018-2968,,"Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported versions that are affected are 16.x, 17.x and 18.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data. CVSS 3.0 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",Oracle,Primavera Unifier,6.5,MEDIUM,0.0008800000068731606,false,,false,false,false,,,false,false,,2018-07-18T13:00:00.000Z,0 CVE-2018-2969,https://securityvulnerability.io/vulnerability/CVE-2018-2969,,Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The supported version that is affected is 16.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).,Oracle,Primavera Unifier,4.3,MEDIUM,0.0004900000058114529,false,,false,false,false,,,false,false,,2018-07-18T13:00:00.000Z,0 CVE-2018-2966,https://securityvulnerability.io/vulnerability/CVE-2018-2966,,"Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported versions that are affected are 16.x, 17.x and 18.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data. CVSS 3.0 Base Score 7.4 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).",Oracle,Primavera Unifier,7.4,HIGH,0.0008800000068731606,false,,false,false,false,,,false,false,,2018-07-18T13:00:00.000Z,0 CVE-2018-2965,https://securityvulnerability.io/vulnerability/CVE-2018-2965,,"Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The supported version that is affected is 16.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",Oracle,Primavera Unifier,6.1,MEDIUM,0.0006900000153109431,false,,false,false,false,,,false,false,,2018-07-18T13:00:00.000Z,0 CVE-2018-2967,https://securityvulnerability.io/vulnerability/CVE-2018-2967,,"Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported versions that are affected are 16.x, 17.x and 18.x. Easily exploitable vulnerability allows physical access to compromise Primavera Unifier. While the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",Oracle,Primavera Unifier,5.3,MEDIUM,0.000859999970998615,false,,false,false,false,,,false,false,,2018-07-18T13:00:00.000Z,0 CVE-2018-2620,https://securityvulnerability.io/vulnerability/CVE-2018-2620,,"Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Platform). Supported versions that are affected are 10.x, 15.x, 16.x and 17.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Primavera Unifier accessible data as well as unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",Oracle,Primavera Unifier,8.1,HIGH,0.0010900000343099236,false,,false,false,false,,,false,false,,2018-01-18T02:00:00.000Z,0 CVE-2017-10149,https://securityvulnerability.io/vulnerability/CVE-2017-10149,,"Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N).",Oracle,Primavera Unifier,4.8,MEDIUM,0.0008099999977275729,false,,false,false,false,,,false,false,,2017-08-08T15:00:00.000Z,0 CVE-2017-10150,https://securityvulnerability.io/vulnerability/CVE-2017-10150,,"Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",Oracle,Primavera Unifier,4.3,MEDIUM,0.0008099999977275729,false,,false,false,false,,,false,false,,2017-08-08T15:00:00.000Z,0 CVE-2017-3501,https://securityvulnerability.io/vulnerability/CVE-2017-3501,,"Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.0, 10.1, 15.1 and 15.2. Easily ""exploitable"" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",Oracle,Primavera Unifier,6.1,MEDIUM,0.0013299999991431832,false,,false,false,false,,,false,false,,2017-04-24T19:00:00.000Z,0