Impact
An unauthenticated attacker who can reach JD Edwards EnterpriseOne General Ledger via HTTP can exploit a difficult‑to‑exploit flaw in version 9.2 that allows the attacker to cause the application to crash repeatedly, leading to a denial of service. In addition to availability damage, the vulnerability permits the attacker to update, insert, or delete accessible data and to read a subset of the data, exposing confidential information. The weakness is improper access control, as the application fails to enforce proper authorization checks and to protect confidential data.
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne General Ledger, component E1 Foundation, version 9.2. The product is accessed over HTTP and the vulnerability is present only in the 9.2 release.
Risk and Exploitability
The CVSS 3.1 score of 7.0 indicates a high likelihood of availability impact while confidentiality and integrity are affected at a low level. The EPSS score of less than 1 % suggests that exploit attempts are very rare at present, and the vulnerability is not listed in the CISA KEV catalog, implying it is not commonly exploited in the wild. Nevertheless, because the vector is remote and unauthenticated, an attacker with network access can reach the vulnerable points solely over HTTP, and successful exploitation requires the attacker to trigger specific application logic that permits data manipulation. Given the difficulty of exploiting the flaw, exploitation is unlikely to succeed without in‑depth knowledge of the application internals, but the impact—if achieved—would be significant.
OpenCVE Enrichment