Oracle JD Edwards Web Runtime SEC Unauthenticated Data Exposure Vulnerability

Vulnerability

A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized read access to certain JD Edwards EnterpriseOne Tools data.

Impact

Exploitation of this vulnerability could result in unauthorized access to a subset of data within JD Edwards EnterpriseOne Tools.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.6
exploitability
7.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.