Impact
A flaw in the installation security mechanism of Oracle JD Edwards EnterpriseOne Tools allows a high‑privileged attacker who can log onto the host where the tools run to create, delete, or modify critical data. The vulnerability is easily exploitable and the impact is restricted to integrity, as the attacker can alter any data accessible to the tools. This weakness reflects an improper access control flaw (CWE‑284). While the description limits the direct impact to JD Edwards EnterpriseOne Tools, the vulnerability can potentially change scope and affect additional downstream JD Edwards components.
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne Tools version 9.2.26.3 is the only fully documented affected release. The issue is specific to the Installation Security component of the tools but may extend to other JD Edwards products, due to a scope change, if they share the same installation context or data store.
Risk and Exploitability
The CVSS v3.1 base score is 6.0, indicating a moderate severity with a focus on integrity. The CVSS vector indicates no (AV:L) and requires high privileges (PR:H), with no user interaction (UI:N). The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Given that the attack requires a local privileged account, the risk for an external adversary is low, but for internal or disgruntled employees the likelihood rises. Organizations should therefore consider that this can lead to significant data corruption if unaddressed.
OpenCVE Enrichment