Impact
A vulnerability in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools permits an unauthenticated attacker who can reach the system via standard HTTP to take full control of the Tools installation. This weakness is classified as CWE-306, indicating missing authentication checks. The flaw allows the attacker to gain unrestricted access, resulting in potential disclosure, modification, or destruction of data as it compromises the entire system. The impact is severe, touching confidentiality, integrity, and availability and effectively enabling a system takeover.
Affected Systems
Oracle JD Edwards EnterpriseOne Tools version 9.2.26.3 is affected. The description indicates that only this exact supported release contains the flaw; other versions are not listed as vulnerable. Users running this version should verify their deployment and ensure it is not exposed to the public internet.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 classifies the flaw as high severity, while the EPSS score of less than 1% suggests currently a very low, but non‑zero probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, indicating no confirmed exploitation in the public domain yet. The attack vector is inferred to be network‑based, requiring only HTTP access and no authentication, and the difficulty is considered high for successful exploitation.
OpenCVE Enrichment