Impact
The vulnerability resides in the Business Logic Infra SEC component of Oracle JD Edwards EnterpriseOne Tools and permits a low‑privileged attacker who has network access via HTTP to perform unauthorized create, delete, or modify operations on critical data. The attack does not require authentication or can bypass existing authentication controls, and the demonstrated impact includes both confidentiality and integrity violations, as reflected by a CVSS 3.1 Base Score of 8.1. Successful exploitation allows an attacker to gain full data access or alter stored information, thereby compromising the integrity of the JD Edwards data store.
Affected Systems
Oracle JD Edwards EnterpriseOne Tools, versions 9.2.0.0 through 9.2.26.4, are affected. Network traffic to the HTTP interface must be able to reach the tool, and the vulnerability is exploitable by a low‑privileged user or script that can send HTTP requests to the system.
Risk and Exploitability
The high CVSS score combined with the absence of an EPSS score suggests a serious but currently unquantified risk. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed public exploits at the time of analysis. An attacker with minimal privileges and network connectivity can exploit the weakness; no special conditions or privileged credentials are required beyond basic network reachability. The exploitation path is straightforward: an unauthenticated or minimally authorized HTTP request triggers the vulnerable business logic, resulting in unauthorized data manipulation.
OpenCVE Enrichment