Impact
The vulnerability in Oracle JD Edwards EnterpriseOne Advanced Pricing – Procurement 9.2 allows an attacker with low privilege who can reach the JDENET network interface to compromise the system. Successful exploitation can result in complete takeover, giving the attacker full control over the application and thereby affecting confidentiality, integrity, and availability. The CVSS 3.1 base score of 7.5 reflects these broad impacts.
Affected Systems
Affected is Oracle JD Edwards EnterpriseOne Advanced Pricing – Procurement version 9.2, used by Oracle Corporation. The vulnerability is limited to this product version and is accessed through the JDENET network communication channel.
Risk and Exploitability
The CVSS score indicates high severity, but the EPSS score below 1 % means real‑world exploitation is considered unlikely at present and the issue is not in the CISA KEV catalog. The attack vector is network‑based (AV:N), requires that the attacker obtain low‑privilege credentials (PR:L), and does not need user interaction (UI:N). If an attacker can reach JDENET and supply suitable input, they can gain complete control of the application.
OpenCVE Enrichment