PatchSiren cyber security CVE debrief
CVE-2017-3324 Oracle CVE debrief
CVE-2017-3324 is a critical Oracle Primavera P6 Enterprise Project Portfolio Management Web Access vulnerability published on 2017-01-27. Oracle/NVD identify affected versions 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, and 16.2, and the issue is reachable over HTTP by an unauthenticated attacker. Successful exploitation can affect confidentiality, integrity, and availability, including unauthorized data changes, data access, and partial denial of service.
- Vendor
- Oracle
- Product
- Primavera P6 Enterprise Project Portfolio Management
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle Primavera P6 EPPM administrators, application owners, security teams, and infrastructure teams responsible for Web Access deployments—especially any instances reachable from untrusted networks.
Technical summary
NVD rates the issue CVSS v3.0 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L). The record describes an unauthenticated network attack via HTTP against Primavera P6 EPPM Web Access and lists affected releases 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, and 16.2. NVD classifies the weakness as NVD-CWE-noinfo, so the source corpus does not identify the underlying flaw type.
Defensive priority
Immediate
Recommended defensive actions
- Apply Oracle's January 2017 CPU/security update referenced in the vendor advisory to all affected Primavera P6 EPPM deployments.
- Inventory Primavera P6 Enterprise Project Portfolio Management Web Access instances and confirm whether versions 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, or 16.2 are present.
- Restrict HTTP exposure to trusted administrative networks until remediation is confirmed.
- Monitor for unauthorized data creation, deletion, modification, and unusual access to Primavera P6 EPPM data.
- Check patch status across all environments and upgrade or retire instances where a supported fix cannot be verified.
Evidence notes
This debrief is based only on the supplied NVD record and the Oracle/SecurityFocus references attached to it. The source corpus confirms the affected versions, the unauthenticated HTTP attack path, and the severe CIA impact. NVD labels the weakness as NVD-CWE-noinfo, so the specific root cause is not disclosed in the provided sources. The CVE was published on 2017-01-27 and the NVD record was later modified on 2026-05-13.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3324 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3324
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3324 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3324
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.