Impact
Based on the description, the flaw appears to be an authentication bypass (CWE-287) and improper access control (CWE-284) – these CWE identifiers are inferred for analysis purposes – and permits unauthenticated attackers who can reach the service over HTTP to compromise the application, potentially taking full control. The repercussions include confidentiality, integrity, and availability loss, as reflected in the CVSS 3.1 base score of 9.8.
Affected Systems
Oracle JD Edwards EnterpriseOne Tools, versions 9.2.0.0 through 9.2.26.4, are affected according to the vendor’s advisory.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of 0.00358 indicates a very low but non‑zero probability of exploitation, yet the lack of required credentials and the ease of exploitation suggest a high likelihood of real‑world attacks. Although the vulnerability is not listed in the CISA KEV catalog, its remote takeover potential makes it a top‑priority risk for deployments exposed to the public or untrusted networks.
OpenCVE Enrichment