Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability

Vulnerability

A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within JD Edwards EnterpriseOne Tools.

Impact

Exploitation of this vulnerability allows for unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.