Impact
The JD Edwards EnterpriseOne Procurement and Subcontract Management version 9.2 contains an access control flaw that allows a low-privileged user with network connectivity over HTTP to gain full control of the application. The vulnerability is based on missing authentication weaknesses, as indicated by the associated CWE. Attackers can compromise confidentiality, integrity, and availability by exploiting this flaw, resulting in complete takeover of the procurement system.
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne Procurement and Subcontract Management product, specifically version 9.2, is the affected suite. The issue resides within the Procurement component and impacts the entire application’s operational integrity.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity rating, while the EPSS score of less than 1% suggests a very low likelihood of widespread exploit activity at the present time. The flaw is not listed in the CISA KEV catalog. An attacker would require only low-level privileges and access to the HTTP interface, making the condition for exploitation minimal but potentially devastating should it be successful.
OpenCVE Enrichment