Oracle Primavera Unifier Multiple Vulnerabilities (Jul 2019 CPU)

High Nessus Plugin ID 126829

Synopsis

An application running on the remote web server is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the Oracle Primavera Unifier installation running on the remote web server is 15.x or 16.x prior to 16.2.15.9 or 17.7.x prior to 17.12.11 or 18.x prior to 18.8.11. It is, therefore, affected by multiple vulnerabilities:

- A deserialization vulnerability exists in the Apache Solr subcomponent of Primavera Unifier. An unauthenticated, remote attacker can exploit this, via a specially crafted request to the Solr Config API, to execute arbitrary code on the target host. (CVE-2019-0192)

- A denial of service (DoS) vulnerability exists in the Apache Tika subcomponent of Primavera Unifier due to incorrect parsing of a crafted sqlite file. An unauthenticated, remote attacker can exploit this issue by convincing a user to open a specially crafted file to cause the application to stop responding. (CVE-2018-17197)

- A server side request forgery exists in the Apache Solr subcomponent of Primavera Unifier. An unauthenticated remote attacker can exploit this issue to make Solr perform an HTTP GET request to any reachable URL.
(CVE-2017-3164)

- A cross-site scripting (XSS) vulnerability exists due to improper validation of user-supplied input before returning it to users. An unauthenticated, remote attacker can exploit this, by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session, which could lead to unauthorized read, update, insert or delete access to a subset of Primavera Unifier data.
(CVE-2015-9251)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Oracle Primavera Unifier version 16.2.15.9 / 17.12.11 / 18.8.11 or later.

See Also

http://www.nessus.org/u?9aa2b901

Plugin Details

Severity: High

ID: 126829

File Name: oracle_primavera_unifier_cpu_jul_2019.nasl

Version: 1.1

Type: remote

Family: CGI abuses

Published: 2019/07/19

Updated: 2019/07/19

Dependencies: 101904

Risk Information

Risk Factor: High

CVSS Score Source: CVE-2019-0192

CVSS v2.0

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: x-cpe:/a:oracle:primavera_unifier

Required KB Items: installed_sw/Oracle Primavera Unifier, www/weblogic

Patch Publication Date: 2019/07/17

Vulnerability Publication Date: 2019/07/17

Reference Information

CVE: CVE-2017-3164, CVE-2015-9251, CVE-2018-17197, CVE-2019-0192

BID: 105658, 106293, 107026, 107318