Impact
The vulnerability lies in the configuration management component of Oracle JD Edwards EnterpriseOne Configurator and allows a low‑privileged attacker with network access via HTTP to perform unauthorized updates, inserts, or deletes, as well as read a subset of accessible data. In addition, successful exploitation can cause the Configurator to hang or crash repeatedly, leading to a denial of service. The CVSS 3.1 score of 6.4 reflects medium confidentiality impact, low integrity impact and high availability impact, indicating a significant threat to system integrity and availability.
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne Configurator version 9.2 is affected. No other versions are listed as impacted in the CNA data.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of exploitation at the current time, and the vulnerability is not included in the CISA KEV catalog. Exploitation requires an attacker to have network access to the HTTP interface and to be a low‑privileged user. Because the attack is difficult and the impact involves both denial of service and unauthorized data changes, organizations should prioritize patching. The CVSS score of 6.4 categorizes it as a medium‑severity vulnerability, but the presence of data alteration and service disruption warrants prompt remediation.
OpenCVE Enrichment