Impact
The flaw in the Human Resources component of JD Edwards EnterpriseOne allows a low privileged attacker with network access via HTTP to exploit a weakness. An authenticated user with low privileges can perform the exploit and gain complete control of the system, compromising confidentiality, integrity, and availability. The vulnerability is a classic missing access‑control issue.
Affected Systems
Oracle Corporation JD Edwards EnterpriseOne Human Resources Management version 9.2 is affected. This product processes HR data and is typically exposed to corporate intranets or the public internet via HTTP.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is via HTTP requests to the HR web interface from any host with network access. The CVSS score of 8.8 reflects a high severity impact. The EPSS score is below 1 %, indicating a low probability of current exploitation, and the vulnerability has not been listed in the CISA KEV catalog. However, because the attack vector is network‑based and requires only low privileges, an attacker can reach the target from anywhere in the network. Exploitation would involve sending specially crafted HTTP requests to the HR web interface, resulting in code execution and full administrative takeover.
OpenCVE Enrichment