Impact
The vulnerability resides in the Installation Security component of JD Edwards EnterpriseOne Tools, permitting an attacker who has local access to the host infrastructure (no additional privileges required) to compromise the application. A successful exploitation can affect additional components due to the scope change, resulting in a full takeover of JD Edwards EnterpriseOne Tools. The CVSS vector indicates that confidentiality, integrity, and availability are fully impacted, and no user interaction is required.
Affected Systems
Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 through 9.2.26.2 are affected. No other product variants are listed in the CVE report.
Risk and Exploitability
The CVSS base score is 9.3, placing the flaw in the Critical severity range. Although the EPSS score is under 1 % and it is not listed in the CISA KEV catalog, the local nature of the attack combined with the scope change means that any host compromise could lead to a full takeover of JD Edwards services. Based on the description, the likely attack vector is local access to the infrastructure where JD Edwards is installed, with no privileged escalation required.
OpenCVE Enrichment