Impact
The JD Edwards EnterpriseOne Accounts Payable product in version 9.2 contains an easily exploitable flaw that allows a low privileged network user to compromise the application via HTTP. The vulnerability provides full loss of confidentiality, integrity and availability of the system, effectively leading to a takeover of JD Edwards EnterpriseOne Accounts Payable. The weakness corresponds to improper access control (CWE-284) with an additional information disclosure risk (CWE-200).
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne Accounts Payable, version 9.2 is the affected product. No other specific product versions are listed, and the impact may extend to other JD Edwards applications due to potential scope change.
Risk and Exploitability
The CVSS v3.1 base score of 9.9, combined with an EPSS score of less than 1%, indicates a very severe vulnerability that is only marginally likely to be exploited in the wild, and it is not currently present in the CISA KEV catalog. Exploitation appears to require an attacker having network access to the HTTP interface and a low‑privileged user account; from there, the attacker can send a crafted request to gain full control of the application.
OpenCVE Enrichment