Impact
The vulnerability resides in JD Edwards EnterpriseOne Tools’ Installation Security and can be exploited by a low‑privileged attacker with network access to the application over HTTP. Successful exploitation allows the attacker to fully take over the JD Edwards EnterpriseOne Tools instance, resulting in loss of confidentiality, integrity and availability of the system, and possibly affecting other connected JD Edwards products due to the scope change.
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne Tools, version 9.2.26.3. The issue may also impact additional JD Edwards products that interface with the compromised Tools installation.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, and the EPSS score of less than 1% signifies a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote HTTP request from an attacker with low privileges; the problem is readily exploitable thanks to the lack of proper access controls, and the scope change allows privilege escalation or cross‑product damage.
OpenCVE Enrichment