Impact
A flaw in the JD Edwards EnterpriseOne HCM Foundation 9.2 OW HR PR Foundation component lets an attacker who can reach the application’s HTTP interface send a crafted request that causes the service to hang or crash, resulting in a complete denial of service. The same request also permits reading a subset of data that should be protected, giving the attacker unauthorized access to sensitive information. The CVSS 3.1 vector, AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H, indicates that the vulnerability can be triggered by a low‑privileged network user without user interaction, producing low confidentiality loss but high availability loss.
Affected Systems
The vulnerability affects Oracle JD Edwards EnterpriseOne HCM Foundation version 9.2. No other Oracle products or versions are listed as impacted by the CNA.
Risk and Exploitability
Because the attack can be launched over an open HTTP port and the required privilege level is low, the EPSS score of less than 1% indicates a low but nonzero chance of exploitation. The CVSS Base 7.1 reflects moderate to high impact on confidentiality and high impact on availability. The vulnerability is not yet in CISA’s KEV catalog. In practice an attacker would send a specialized HTTP request to the OW HR PR Foundation endpoint, which triggers both the denial of service and the data leak; the lack of a user‑interaction requirement means the attack can be carried out automatically from any networked machine that can reach the target.
OpenCVE Enrichment