Impact
The vulnerability in the Human Resources component of Oracle JD Edwards allows a low‑privileged attacker who can reach the system through JDENET to compromise the application. Exploitation can lead to full takeover of the HR module, exposing or altering confidential employee data and disrupting HR services. The weakness results in confidentiality, integrity, and availability loss, as reflected by the CVSS vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.
Affected Systems
The affected product is Oracle JD Edwards EnterpriseOne Human Resources Management 9.2. Only the 9.2 release is mentioned as vulnerable, and the flaw resides in the Human Resources component. No other versions are currently known to be impacted.
Risk and Exploitability
With a CVSS base score of 7.5 the vulnerability is considered high severity. The EPSS score is less than 1%, indicating that the probability of exploitation in the wild is currently low, and it is not listed in the CISA KEV catalog. However, the attack vector requires network access via JDENET and the attacker only needs low privileges, meaning that an internal threat actor with access to that network could attempt the exploit. Because the flaw is difficult to exploit, organizations should still mitigate promptly.
OpenCVE Enrichment