Impact
The vulnerability exists in the JD Edwards EnterpriseOne US Payroll component and allows an attacker who has network access to JDENET and only low‑level privileges to compromise the entire payroll system. This is an Authorization Bypass (CWE-284) flaw that permits full takeover, impacting confidentiality, integrity, and availability.
Affected Systems
Oracle JD Edwards EnterpriseOne US Payroll version 9.2 is the only affected configuration documented. No other products or versions are listed, so the risk is confined to this specific release.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 signals moderate to high severity. Attackers need only network connectivity to JDENET and low privileges; no user interaction is required. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A successful exploitation would result in a full takeover of the payroll system.
OpenCVE Enrichment