Impact
A flaw in Oracle JD Edwards EnterpriseOne HCM Foundation version 9.2 allows a low‑privileged attacker who can reach the system over HTTP to gain full control of the application. The vulnerability exists in the Time Accounting and HRM Base components and, if exploited, permits the attacker to read, modify or delete data and disrupt the availability of the system, affecting confidentiality, integrity and availability.
Affected Systems
The vulnerability targets Oracle JD Edwards EnterpriseOne HCM Foundation 9.2, specifically its Time Accounting and HRM Base modules. All installations of this release that include those modules are susceptible unless already patched.
Risk and Exploitability
The CVSS base score of 7.5 signals a high severity threat; however, the EPSS score of less than 1% indicates the likelihood of immediate exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. Attackers only need low privileges and network connectivity over HTTP, so the attack can be launched from a host that has network access to the JD Edwards servers. It is inferred that the attacker’s access could be internal or from an exposed network, as the description does not specify the exact attack surface, but it requires an HTTP connection to the vulnerable system.
OpenCVE Enrichment