CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Oracle MySQL InnoDB Component Denial-of-Service and Data Manipulation Vulnerability
A vulnerability exists in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. Affected versions include 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability is easily exploitable and allows a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause a hang or a frequently repeatable crash, resulting in a complete denial-of-service for the MySQL Server. Additionally, it allows unauthorized update, insert, or delete access to some data accessible by the MySQL Server.
Oracle Primavera P6 EPPM Web Access Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability has been identified in the Web Access component of Oracle Primavera P6 Enterprise Project Portfolio Management, affecting versions 20.12.1.0 through 20.12.21.5, 21.12.1.0 through 21.12.20.0, and 22.12.1.0. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Primavera P6 EPPM. Exploitation requires human interaction from a third party. While the vulnerability is specific to Primavera P6 EPPM, successful attacks could significantly impact other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized read access to certain Primavera P6 EPPM data, as well as unauthorized update, insert, or delete access to some accessible data.
Oracle Application Express General Vulnerability Allowing Data Manipulation and Unauthorized Access
A vulnerability has been identified in Oracle Application Express, specifically in versions 23.2 and 24.1. This easily exploitable issue allows a low-privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful exploitation requires human interaction from someone other than the attacker. While the vulnerability resides within Oracle Application Express, its effects may extend to other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized updates, inserts, or deletions of data accessible through Oracle Application Express, as well as unauthorized read access to certain subsets of that data.
Oracle Agile PLM Framework Integration Services Takeover Vulnerability
A vulnerability allowing takeover of the Oracle Agile PLM Framework has been identified in version 9.3.6 of the product. This easily exploitable issue affects the Agile Integration Services component and allows low privileged attackers with network access via HTTP to compromise the framework. While the vulnerability resides within Oracle Agile PLM Framework, successful exploitation could significantly impact additional products.
Oracle MySQL Server InnoDB Component Denial-of-Service and Data Manipulation Vulnerability
A vulnerability exists in the InnoDB component of Oracle MySQL Server, affecting versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability allows a high-privileged attacker with network access to MySQL Server to cause a complete denial-of-service by hanging or crashing the server. Additionally, the vulnerability permits unauthorized access to manipulate some of the data accessible to MySQL Server.
Oracle Communications Order and Service Management Unauthenticated Data Exposure Vulnerability
A vulnerability exists in Oracle Communications Order and Service Management versions 7.4.0, 7.4.1, and 7.5.0, within the Security component. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can lead to unauthorized read access to certain accessible data within Oracle Communications Order and Service Management.
Oracle Database Server Java VM Vulnerability Allowing Unauthorized Data Access
A vulnerability has been identified in the Java VM component of Oracle Database Server. It affects versions 19.3 through 19.25, 21.3 through 21.16, and 23.4 through 23.6. This vulnerability is difficult to exploit but allows a low-privileged attacker with Create Session and Create Procedure privileges, and network access via Oracle Net, to compromise the Java VM. Successful exploitation could lead to unauthorized modification, addition, or deletion of certain Java VM accessible data, as well as unauthorized reading of a subset of that data.
Oracle JD Edwards EnterpriseOne Orchestrator Vulnerability in E1 IOT Orchestrator Security Allowing Unauthorized Data Access
A vulnerability exists in Oracle JD Edwards EnterpriseOne Orchestrator, specifically in the E1 IOT Orchestrator Security component, affecting versions prior to 9.2.9.2. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTP to compromise the Orchestrator. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible through JD Edwards EnterpriseOne Orchestrator.
Oracle Solaris File System Vulnerability Allowing Data Manipulation and Denial-of-Service
A vulnerability has been identified in the Oracle Solaris product, specifically in the file system component of Oracle Systems version 11. This easily exploitable vulnerability allows a high-privileged attacker with logon access to the Oracle Solaris environment to compromise the system. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, as well as all data accessible by Oracle Solaris. Additionally, this vulnerability could be exploited to cause a complete denial-of-service by hanging the system or causing frequent, repeatable crashes.
Oracle Financial Services Behavior Detection Platform Web UI Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Financial Services Behavior Detection Platform, specifically in the Web UI component, affecting versions 8.0.8.1, 8.1.2.7, and 8.1.2.8. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the Behavior Detection Platform. Exploitation of this vulnerability requires human interaction from a third party. While the vulnerability is contained within the Behavior Detection Platform, successful attacks could significantly impact other Oracle Financial Services applications. The vulnerability allows for unauthorized read access to certain accessible data, as well as unauthorized update, insert, or delete access to some data within the Behavior Detection Platform.
Oracle WebLogic Server Core Component Denial-of-Service Vulnerability via HTTP/2
A denial-of-service vulnerability has been identified in Oracle WebLogic Server version 14.1.1.0.0, part of Oracle Fusion Middleware. This vulnerability allows an unauthenticated attacker with network access via HTTP/2 to disrupt the server's availability. Exploitation of this issue can lead to a complete hang or a frequently repeatable crash of the WebLogic Server.
Oracle MySQL Connector/Python Vulnerability Allowing Data Manipulation and Denial-of-Service
A vulnerability exists in Oracle MySQL Connectors, specifically in Connector/Python, affecting versions through 9.1.0. This easily exploitable issue allows a high-privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Exploitation requires human interaction from a third party. Successful attacks could lead to unauthorized creation, deletion, or modification of critical data, access to a subset of MySQL Connectors data, and the ability to cause a complete denial-of-service by hanging or crashing MySQL Connectors.
Oracle Hospitality OPERA 5 Unauthenticated HTTP Vulnerability Allowing Data Access and Denial-of-Service
A vulnerability exists in Oracle Hospitality OPERA 5 versions 5.6.19.20, 5.6.25.8, 5.6.26.6, and 5.6.27.1 within the Opera Servlet component. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation can lead to unauthorized access to critical data or complete access to all accessible data in Oracle Hospitality OPERA 5, as well as the unauthorized ability to cause a complete denial-of-service by hanging the application or causing it to crash frequently and repeatably.
Oracle MySQL Server Privilege Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in Oracle MySQL Server in versions through 8.0.40, 8.4.3 and 9.1.0. This easily exploitable issue allows a high-privileged attacker with network access to compromise the MySQL Server. Successful exploitation could lead to unauthorized modification, insertion, or deletion of data accessible to the MySQL Server, as well as unauthorized reading of certain data subsets.
Oracle PeopleSoft OpenSearch Component Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the OpenSearch component of Oracle PeopleSoft Enterprise PeopleTools, affecting versions 8.60 and 8.61. This vulnerability allows an unauthenticated attacker with network access via HTTP to cause a complete hang or crash of the PeopleTools application.
Oracle Communications Order and Service Management Security Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability has been identified in the Oracle Communications Order and Service Management product, specifically in versions 7.4.0, 7.4.1, and 7.5.0. This vulnerability, which resides in the Security component, is easily exploitable by low-privileged attackers with network access via HTTP. Successful exploitation requires human interaction from someone other than the attacker. While the vulnerability is contained within Oracle Communications Order and Service Management, successful attacks could significantly impact additional products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized read access to certain subsets of accessible data, as well as unauthorized update, insert, or delete access to other accessible data within Oracle Communications Order and Service Management.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle Communications Order and Service Management Security Vulnerability Allowing Unauthorized Data Access and Partial Denial-of-Service
A vulnerability has been identified in the Oracle Communications Order and Service Management product, specifically in versions 7.4.0, 7.4.1, and 7.5.0. This vulnerability, which resides in the Security component, is easily exploitable by low-privileged attackers with network access via HTTP. Successful exploitation allows unauthorized users to update, insert, or delete certain accessible data within Oracle Communications Order and Service Management. Additionally, it permits unauthorized read access to a subset of accessible data and the ability to cause a partial denial-of-service on the application.
Oracle E-Business Suite Workflow Vulnerability in Admin Screens and Grants UI Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Workflow component of Oracle E-Business Suite, specifically within the Admin Screens and Grants UI. This issue affects versions 12.2.3 through 12.2.14. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful exploitation could lead to unauthorized read access to certain Oracle Workflow data, as well as unauthorized updates, inserts, or deletions of other accessible data.
Oracle MySQL Server Privileges Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in Oracle MySQL Server in versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability allows a low-privileged attacker with network access to compromise the MySQL Server. Exploitation of this vulnerability could lead to unauthorized read access, as well as unauthorized update, insert, or delete access to some data accessible by the MySQL Server.
Oracle PeopleSoft FIN eSettlements Vulnerability Allows Unauthorized Data Access and Modification
A vulnerability exists in the PeopleSoft Enterprise FIN eSettlements product, specifically in version 9.2. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise the application. Exploitation of this vulnerability could lead to unauthorized read, update, insert, or delete access to certain accessible data within the eSettlements component.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.2. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, its effects may extend to other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized read access to certain JD Edwards EnterpriseOne Tools data, as well as unauthorized update, insert, or delete access to other accessible data.
Oracle PeopleSoft Cash Management Unauthorized Data Access and Modification Vulnerability
A vulnerability exists in Oracle PeopleSoft Enterprise FIN Cash Management version 9.2, specifically within the Cash Management component. This easily exploitable issue allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation could lead to unauthorized read access to certain subsets of accessible data, as well as unauthorized updates, inserts, or deletions of some data within PeopleSoft Enterprise FIN Cash Management.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects supported versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle WebLogic Server Core Component Unauthorized Remote Takeover Vulnerability
A vulnerability exists in Oracle WebLogic Server within the Oracle Fusion Middleware suite, specifically in the Core component. This issue affects version 12.2.1.4.0 and 14.1.1.0.0. The vulnerability allows an unauthenticated attacker with network access via T3 or IIOP to compromise the WebLogic Server. Exploitation of this vulnerability can lead to a complete takeover of the server.
Oracle MySQL Server Performance Schema Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server component of Oracle MySQL. This issue affects versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle VM VirtualBox Core Component Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in the Oracle VM VirtualBox product, specifically in the Core component, affecting versions prior to 7.0.24 and prior to 7.1.6. This easily exploitable vulnerability allows a low-privileged attacker with access to the infrastructure where Oracle VM VirtualBox runs to compromise the application. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible through Oracle VM VirtualBox.
Oracle Analytics Desktop Vulnerability Allowing Takeover on Affected Versions Prior to 8.1.0
A vulnerability exists in the Install component of Oracle Analytics Desktop, specifically in versions prior to 8.1.0. This easily exploitable issue allows a low-privileged attacker with access to the environment where Oracle Analytics Desktop runs to compromise the application. Successful exploitation can lead to a complete takeover of Oracle Analytics Desktop.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. This issue affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle PeopleSoft Enterprise PeopleTools Panel Processor Vulnerability Allowing Unauthorized Data Access
A vulnerability has been identified in the PeopleSoft Enterprise PeopleTools product, specifically within the Panel Processor component. This issue affects versions 8.60 and 8.61. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful exploitation of this vulnerability could lead to unauthorized read access to certain data within PeopleSoft Enterprise PeopleTools.
Oracle MySQL Server Denial-of-Service Vulnerability in Information Schema Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Server: Information Schema component. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle Primavera P6 EPPM Web Access Unauthenticated Data Modification Vulnerability
An easily exploitable vulnerability has been identified in the Web Access component of Oracle Primavera P6 Enterprise Project Portfolio Management. This vulnerability affects versions 20.12.1.0 through 20.12.21.5, 21.12.1.0 through 21.12.20.0, 22.12.1.0 through 22.12.16.0, and 23.12.1.0 through 23.12.10.0. The issue allows an unauthenticated attacker with network access via HTTP to compromise Primavera P6 EPPM. Exploitation of this vulnerability requires human interaction from a third party. Successful attacks can lead to unauthorized update, insert, or delete access to some of the data accessible in Primavera P6 EPPM.
Oracle JD Edwards EnterpriseOne Tools Design Tools Security Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically within the Design Tools component, for versions prior to 9.2.9.0. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the affected tools. Exploitation of this vulnerability requires human interaction from a person other than the attacker. While the issue is contained within JD Edwards EnterpriseOne Tools, successful attacks could significantly impact additional products, leading to a scope change. The vulnerability allows unauthorized update, insert, or delete access to some accessible data within JD Edwards EnterpriseOne Tools, as well as unauthorized read access to a subset of that data.
Oracle Primavera P6 EPPM Web Access Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability has been identified in the Web Access component of Oracle Primavera P6 Enterprise Project Portfolio Management, affecting versions 20.12.1.0 through 20.12.21.5, 21.12.1.0 through 21.12.20.0, 22.12.1.0 through 22.12.16.0, and 23.12.1.0 through 23.12.10.0. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Primavera P6 EPPM. Exploitation requires human interaction from a third party. While the vulnerability resides within Primavera P6 EPPM, successful attacks could significantly impact other products, leading to a scope change. Exploiting this vulnerability could result in unauthorized read, update, insert, or delete access to certain accessible data within Primavera P6 EPPM.
Oracle MySQL Server Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. This vulnerability allows a high-privileged attacker with network access to MySQL Server via multiple protocols to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the MySQL Server.
Oracle JD Edwards EnterpriseOne Tools Monitoring and Diagnostics SEC Unauthenticated Takeover Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Monitoring and Diagnostics SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to a complete takeover of the application.
Oracle MySQL InnoDB Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically within the InnoDB component. This issue affects supported versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a high-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in the Parser Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Parser component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable, allowing a low-privileged attacker with network access via multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Thread Pooling Denial-of-Service Vulnerability
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Server: Thread Pooling component. This vulnerability affects MySQL Server versions 8.0.39 and prior, 8.4.2 and prior, and 9.0.1 and prior. The issue is easily exploitable, allowing an unauthenticated attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to unauthorized actions causing the server to hang or crash frequently, resulting in a complete denial-of-service condition.
Oracle MySQL Server Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in Oracle MySQL Server in versions through 8.0.40, 8.4.3 and 9.1.0. This difficult-to-exploit vulnerability allows a high-privileged attacker with access to the MySQL Server environment to compromise the server. Exploitation requires human interaction from a third party. Successful attacks could lead to unauthorized read access to certain data within MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Privileges Component
A denial-of-service vulnerability has been identified in Oracle MySQL Server, specifically in the Privileges component of the Security feature. This issue affects MySQL versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is difficult to exploit but allows a high-privileged attacker with network access through multiple protocols to disrupt MySQL Server operations. Successful exploitation can lead to a complete hang or a frequently repeatable crash of the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in Optimizer Component
A denial-of-service vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically in the Optimizer component. This issue affects MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. The vulnerability is easily exploitable by a low-privileged attacker with network access through multiple protocols, allowing them to cause a hang or a frequently repeatable crash of the MySQL Server, leading to a complete denial-of-service condition.
Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Vulnerability Allowing Unauthorized Data Modification
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized update, insert, or delete access to some data within JD Edwards EnterpriseOne Tools.
Oracle E-Business Suite Customer Care Service Requests Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in the Oracle Customer Care component of Oracle E-Business Suite, specifically in versions 12.2.5 through 12.2.13. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible within Oracle Customer Care.
Oracle JD Edwards EnterpriseOne Tools Web Runtime SEC Vulnerability Allowing Unauthorized Takeover
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized takeover of the application.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Exposure Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized read access to certain JD Edwards EnterpriseOne Tools data.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, its effects may extend to other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete certain data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from a third party. While the vulnerability is contained within JD Edwards EnterpriseOne Tools, it may significantly impact additional products. Exploitation of this vulnerability could lead to unauthorized read access to certain JD Edwards EnterpriseOne Tools data, as well as unauthorized update, insert, or delete access to other accessible data.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, prior to version 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within JD Edwards EnterpriseOne Tools.
Oracle JD Edwards Web Runtime SEC Unauthenticated Data Access Vulnerability
A vulnerability exists in the JD Edwards EnterpriseOne Tools product, specifically in the Web Runtime SEC component, affecting versions prior to 9.2.9.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within JD Edwards EnterpriseOne Tools.
