Impact
The vulnerability is an instance of CWE-284 Improper Access Control in the installation security of JD Edwards EnterpriseOne Tools version 9.2.26.3. An attacker without authentication who gains access to the physical communication segment attached to the hardware can potentially compromise the application. The exploitation requires an additional human interaction beyond the attacker and is difficult; if achieved, it allows the attacker to update, insert, or delete data and read portions of data that should be protected, thereby undermining confidentiality and integrity.
Affected Systems
Oracle Corporation’s JD Edwards EnterpriseOne Tools product, version 9.2.26.3, is affected; no other versions are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 3.7 indicates low impact on confidentiality and integrity, and the EPSS score of less than 1 % reflects a very low probability of exploitation. The flaw is not included in the CISA KEV catalog and is limited to a local physical access scenario. While the overall risk is confined to personnel with physical access, achieving the exploit still requires human interaction beyond the attacker, and the potential for unauthorized data modification warrants timely remediation.
OpenCVE Enrichment