Impact
The JD Edwards EnterpriseOne Orchestrator contains a vulnerability that allows a network attacker with only low privileges to perform unauthorized creation, deletion or modification of critical data through the HTTP interface. The flaw compromises confidentiality and integrity by permitting an attacker to alter any data accessible through the Orchestrator, potentially affecting all client applications that rely on the Orchestrator.
Affected Systems
Oracle JD Edwards EnterpriseOne Orchestrator, versions 9.2.0.0 through 9.2.26.4, is affected by this weakness.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 marks this issue as high severity, and the EPSS score is not available, indicating no current evidence of exploitation but a high likelihood if left unpatched. Attacks would be carried out over HTTP without user interaction and would grant the attacker unauthorized data access at the application level. The vulnerability is listed in CISA KEV as not present, so no publicly known exploits exist, yet the high impact makes it a critical target for attackers.
OpenCVE Enrichment