Impact
The JD Edwards EnterpriseOne Tools product contains an unauthenticated vulnerability in the Enterprise Infrastructure Security component that allows attackers to send HTTP requests without credentials. Successful exploitation can lead to unauthorized access to critical data, full data compromise, or the ability to cause a hang or repeated crash, thereby affecting confidentiality and availability. The vulnerability is classified as a high severity flaw with a CVSS v3.1 score of 9.1.
Affected Systems
Affected systems are Oracle JD Edwards EnterpriseOne Tools releases 9.2.0.0 through 9.2.26.2. The vulnerability applies to all builds of JD Edwards EnterpriseOne Tools that include the Enterprise Infrastructure Security component in that version range. No additional affected versions are listed.
Risk and Exploitability
The CVSS score reflects a high likelihood of successful attack, with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/A:H. The EPSS score of less than 1% indicates a low probability that exploitation is currently occurring in the wild, and the vulnerability is not listed in the CISA KEV catalog. Despite this, an unauthenticated attacker with network access can exploit the flaw over HTTP, so organisations should treat this as a high-risk exposure until a patch is applied.
OpenCVE Enrichment