Impact
Vulnerability resides in the Interoperability Security component of JD Edwards EnterpriseOne Tools, specifically within the JDENET network interface. The flaw allows an unauthenticated attacker who can reach JDENET to compromise the tool, which may result in a partial loss of availability for JD Edwards services. The CVSS v3.1 base score of 3.7 indicates a low severity classification, pointing to a modest impact on availability only, as suggested by the SeV vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L.
Affected Systems
Oracle JD Edwards EnterpriseOne Tools, version 9.2.26.3.
Risk and Exploitability
The EPSS score of less than 1% signals a low probability of active exploitation, and the vulnerability is not current in the CISA KEV catalog. Exploitation requires only network access to JDENET; no user privileges or local access are necessary. Attack complexity is high, making it difficult to execute, but the low overall vulnerability score reflects only a limited availability impact.
OpenCVE Enrichment