PatchSiren cyber security CVE debrief
CVE-2017-3277 Oracle CVE debrief
CVE-2017-3277 is an Oracle Applications Manager (OAM Client) vulnerability in Oracle E-Business Suite that was published on 2017-01-27 and later modified in NVD on 2026-05-13. NVD and Oracle-linked references identify affected versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is rated medium severity (CVSS 4.9) and is focused on confidentiality: a high-privileged attacker with network access via HTTP can access critical or otherwise all OAM-accessible data.
- Vendor
- Oracle
- Product
- Applications Manager
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle E-Business Suite administrators, Oracle Applications Manager owners, identity/access administrators, and vulnerability management teams responsible for high-privilege application access and HTTP exposure.
Technical summary
NVD classifies the weakness as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The CVSS v3.0 vector is AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N, indicating network reachability, low attack complexity, no user interaction, and a requirement for high privileges. The documented impact is confidentiality-only; integrity and availability are not affected in the CVSS vector.
Defensive priority
Medium priority. The vulnerability is exploitable only by a high-privileged attacker, but the potential impact includes unauthorized access to sensitive Oracle Applications Manager data.
Recommended defensive actions
- Apply the Oracle CPU/January 2017 update referenced in Oracle's advisory for the affected Oracle E-Business Suite / Applications Manager versions.
- Verify whether Oracle Applications Manager instances are on one of the affected versions: 12.1.3, 12.2.3, 12.2.4, 12.2.5, or 12.2.6.
- Restrict network access to Oracle Applications Manager to only trusted administrative sources.
- Review and minimize high-privilege access to the application, especially accounts that can reach OAM over HTTP.
- Monitor privileged access and administrative activity for unusual data access patterns in Oracle Applications Manager.
Evidence notes
Based on the NVD CVE record and its linked Oracle advisory reference. NVD lists affected CPEs for Oracle Applications Manager versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6, and the CVSS v3.0 vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N. The record also cites CWE-200. Reference URLs supplied in the corpus include the official CVE record, NVD detail page, and Oracle's January 2017 Critical Patch Update advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3277 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3277
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3277 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3277
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.