Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability

Vulnerability

A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, its effects may extend to other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete certain data within JD Edwards EnterpriseOne Tools.

Impact

Exploitation allows for unauthorized read access to some JD Edwards EnterpriseOne Tools data, as well as unauthorized updates, inserts, or deletions of other accessible data.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
1.3
exploitability
6.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.