Impact
Vulnerability identified in the JD Edwards EnterpriseOne Orchestrator component named E1 IOT Orchestrator Security permits an unauthenticated attacker with network access via TLS to compromise the orchestration layer. Successful exploitation can lead to full takeover of the Orchestrator, potentially giving the attacker control over application configuration, data flows, and the underlying JD Edwards EnterpriseOne system. The risk encompasses confidentiality, integrity, and availability impacts, as indicated by a CVSS 3.1 base score of 8.1.
Affected Systems
This weakness affects Oracle Corporation’s JD Edwards EnterpriseOne Orchestrator, specifically the product versions released from 9.2.0.0 up to and including 9.2.26.4. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The exposure is limited to clients that can reach the Orchestrator over a TLS connection, with no authentication required to trigger the flaw. While the description notes that exploitation is difficult, the combination of a high CVSS score and the lack of an official KEV listing means that organizations should treat it as a high‑risk vulnerability. The EPSS score is not available, so the likelihood of a real‑world exploit is uncertain, but the potential for catastrophic takeover warrants immediate remedial action. Potential attack vectors are simple network connections to the Orchestrator’s TLS endpoint, and once a connection is established the flawed component hands control to the attacker.
OpenCVE Enrichment