Impact
This flaw in Oracle JD Edwards EnterpriseOne CRM Foundation version 9.2 is an access‑control weakness that lets a low‑privileged user who can reach the JDENET interface perform privileged operations. Successful exploitation can lead to a complete takeover of the application, exposing confidential data, altering system state, and disrupting availability. The weakness is categorized as CWE‑306.
Affected Systems
Oracle JD Edwards EnterpriseOne CRM Foundation 9.2 is affected. No other product versions or components are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates high severity with confidentiality, integrity, and availability all impacted. The EPSS score of less than 1 % shows an extremely low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a low‑privileged network user who can access the JDENET interface; exploitation requires no additional privileges or special conditions beyond that network access.
OpenCVE Enrichment