Impact
The issue is a missing authentication flaw that allows an attacker with low‑privilege network access to the JDENET interface to assume control of the JD Edwards EnterpriseOne Requirements Planning application. The vulnerability requires a network connection, a low privilege account, no user interaction, and high attack complexity. Successful exploitation provides full control of the application, leading to loss of confidentiality, integrity and availability of the underlying business data and services. The weakness is a CWE‑306, missing authentication for a critical operation.
Affected Systems
Oracle JD Edwards EnterpriseOne Requirements Planning version 9.2 is affected. Users running JDENET in a networked environment must be aware that any low‑privileged user with access to JDENET can potentially compromise the application.
Risk and Exploitability
The CVSS base score of 7.5 places the vulnerability in the high‑severity range, and the EPSS score of less than 1 % indicates that routine exploitation traffic is currently low. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network reachability to the JDENET interface and a low‑privileged account, making the attack feasible in a networked setting. Although detection of exploitation may be low, the potential for full application takeover warrants prompt attention.
OpenCVE Enrichment