Impact
The JD Edwards EnterpriseOne Tools installation component contains a flaw that permits a low‑privileged attacker with network access to send crafted HTTP requests, resulting in total compromise of the tool. The flaw provides full confidentiality, integrity, and availability loss, and a CVSS 3.1 base score of 8.8 highlights its serious capital. The vulnerability is rooted in inadequate access control, allowing takeover by an attacker who does not require elevated privileges. Affecting only the installation process, the weakness can be leveraged from any externally reachable point without additional authentication or user interaction. Successful exploitation would grant the attacker full control over the JD Edwards EnterpriseOne Tools instance, enabling arbitrary configuration changes, data exfiltration, or service disruption. Risk assessment shows a high likelihood of exploitation in environments where the tool is exposed to the internet. EPSS information is unavailable, but the combination of a high CVSS score, low attack complexity, and lack of privileged access suggests that a competent attacker could weaponize this flaw rapidly. The vulnerability is not listed in the CISA KEV catalog, which does not diminish the need for urgent remediation.
Affected Systems
Affected systems are Oracle Corporation's JD Edwards EnterpriseOne Tools, specifically the Installation Security component for versions 9.2.0.0 through 9.2.26.4. The vulnerability impacts the installation process of these releases and is not present in any later patches beyond 9.2.26.4.
Risk and Exploitability
The vulnerability scores a CVSS 3.1 base of 8.8, with high impact on confidentiality, integrity, and availability. The EPSS score is not available, indicating that no current exploitation data is reported; however, the low attack complexity and lack of privileged access suggest the risk remains high for exposed environments. The vulnerability is not listed in the CISA KEV catalog, so there is no known exploitation but that does not diminish the need for rapid patching. The attack vector is network-based over HTTP, with an attacker only needing to send crafted requests from an external host.
OpenCVE Enrichment