Impact
A vulnerability exists in Oracle JD Edwards EnterpriseOne Solution Advisor 9.2 that enables an attacker with low user privileges who can reach the application over HTTP to compromise the solution. The flaw allows the attacker to take control of the application, affecting confidentiality, integrity, and availability of the component. The vulnerability is documented as an easily exploitable issue that can result in a full takeover of the Solution Advisor.
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne Solution Advisor, version 9.2, is affected. No other versions are listed as vulnerable in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of immediate exploitation in the wild, and the issue is not included in the CISA KEV catalog. The attack vector is remote over HTTP; the attacker requires only low privileges and network access does not need local or elevated privileges to exploit the vulnerability.
OpenCVE Enrichment