CVE-2019-2976 is a vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management (versions 17.1.0-17.12.12), specifically affecting its Web Access component. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical or all accessible data. Successful attacks require user interaction and can impact additional products. With a CVSS v3.0 score of 6.8 (Medium), it primarily impacts confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.1.0, <= 17.12.12CPE matchmatch criteria | cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.