Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Vulnerability Allowing Unauthorized Takeover

Vulnerability

A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized takeover of the application.

Impact

Exploitation of this vulnerability can result in unauthorized takeover of JD Edwards EnterpriseOne Tools.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM