Impact
This is a CWE‑284 Access Control Failure vulnerability in Oracle JD Edwards EnterpriseOne CRM Foundation 9.2 that allows an attacker with low privilege, but network access via HTTP, to gain full control of the application. Successful exploitation permits the attacker to read, modify, or delete data and ultimately have authority over the system, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle JD Edwards EnterpriseOne CRM Foundation 9.2 is the only version identified for compromise. No other editions or releases are listed in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 marks this flaw as high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation in the wild at present, and it is not included in CISA’s Known Exploited Vulnerabilities catalog. The vulnerability can be triggered remotely over HTTP and does not require elevated user rights, making it a straightforward but powerful attack vector for malicious actors.
OpenCVE Enrichment