Oracle · Oracle Primavera Unifier · CVE-2020-14617
**Name of the Vulnerable Software and Affected Versions**
Oracle Primavera Unifier versions 16.1, 16.2, 17.7 through 17.12, 18.8, 19.12
Oracle Primavera Unifier Mobile App versions prior to 20.6
**Description**
The issue is related to inadequate access control in the Primavera Unifier product, allowing a low-privileged attacker with network access via HTTPS to compromise the system. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized access to critical data or complete access to all accessible data.
**Recommendations**
For Oracle Primavera Unifier versions 16.1, 16.2, 17.7 through 17.12, 18.8, 19.12, update to a version later than 19.12.
For Oracle Primavera Unifier Mobile App versions prior to 20.6, update to version 20.6 or later.
As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.