PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3324 Oracle CVE debrief

CVE-2017-3324 is a critical Oracle Primavera P6 Enterprise Project Portfolio Management Web Access vulnerability published on 2017-01-27. Oracle/NVD identify affected versions 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, and 16.2, and the issue is reachable over HTTP by an unauthenticated attacker. Successful exploitation can affect confidentiality, integrity, and availability, including unauthorized data changes, data access, and partial denial of service.

Vendor
Oracle
Product
Primavera P6 Enterprise Project Portfolio Management
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Oracle Primavera P6 EPPM administrators, application owners, security teams, and infrastructure teams responsible for Web Access deployments—especially any instances reachable from untrusted networks.

Technical summary

NVD rates the issue CVSS v3.0 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L). The record describes an unauthenticated network attack via HTTP against Primavera P6 EPPM Web Access and lists affected releases 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, and 16.2. NVD classifies the weakness as NVD-CWE-noinfo, so the source corpus does not identify the underlying flaw type.

Defensive priority

Immediate

Recommended defensive actions

  • Apply Oracle's January 2017 CPU/security update referenced in the vendor advisory to all affected Primavera P6 EPPM deployments.
  • Inventory Primavera P6 Enterprise Project Portfolio Management Web Access instances and confirm whether versions 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, or 16.2 are present.
  • Restrict HTTP exposure to trusted administrative networks until remediation is confirmed.
  • Monitor for unauthorized data creation, deletion, modification, and unusual access to Primavera P6 EPPM data.
  • Check patch status across all environments and upgrade or retire instances where a supported fix cannot be verified.

Evidence notes

This debrief is based only on the supplied NVD record and the Oracle/SecurityFocus references attached to it. The source corpus confirms the affected versions, the unauthenticated HTTP attack path, and the severe CIA impact. NVD labels the weakness as NVD-CWE-noinfo, so the specific root cause is not disclosed in the provided sources. The CVE was published on 2017-01-27 and the NVD record was later modified on 2026-05-13.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-3324 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-3324

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-3324 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3324

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.