Impact
Oracle JD Edwards EnterpriseOne CRM Foundation version 9.2 contains a flaw that permits a low‑privileged attacker with network access to compromise the application. The vulnerability is easily exploitable and can lead to full compromise of confidentiality, integrity, and availability. The weakness is linked to improper access control, authentication bypass, and missing authentication, as indicated by the CWE identifiers.
Affected Systems
The only affected release is JD Edwards EnterpriseOne CRM Foundation 9.2 from Oracle Corporation. Systems running this version expose an HTTP interface that is reachable over the network and are therefore susceptible to the described flaw.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 score of 8.8, indicating high severity for confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests that exploitation is currently uncommon, and the issue is not listed in the CISA KEV catalogue. Based on the description, the likely attack vector is a network‑based HTTP request. An attacker with low privileges—either weak authenticated access or potentially no authentication—could trigger the exploit by sending a crafted request, requiring only basic network connectivity.
OpenCVE Enrichment