Junglewise Threat Intelligence

CVE-2017-3324: Oracle Primavera P6 EPPM unauthenticated compromise in Web Access

CVE-2017-3324 · Severity: critical · CVSS 10 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's project management software that allows an unauthorized person to gain full control over the system via the web interface. An attacker could view, modify, or delete sensitive project data and potentially disrupt business operations. This issue is particularly severe because it requires no login credentials and can be exploited over the internet.

Technical details

A vulnerability in the Web Access subcomponent of Oracle Primavera P6 Enterprise Project Portfolio Management (EPPM) allows an unauthenticated attacker with network access via HTTP to compromise the application. The vulnerability is characterized by a CVSS 3.0 base score of 10.0, indicating high impact on confidentiality, integrity, and availability. While the root cause is not explicitly detailed in the advisory (NVD-CWE-noinfo), the 'Scope: Changed' (S:C) metric suggests that an exploit could impact components beyond the Primavera application itself. Attackers can perform unauthorized creation, deletion, or modification of all accessible data. Affected versions include 8.2 through 16.2.

Affected products

  • Oracle Primavera P6 Enterprise Project Portfolio Management (EPPM) 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, 16.2

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update (CPU) January 2017

References

Related threats