PT-2023-9649 · Oracle · Jd Edwards Enterpriseone Orchestrator

Published

2023-12-07

·

Updated

2024-12-05

·

CVE-2024-21168

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions JD Edwards EnterpriseOne Orchestrator versions prior to 9.2.8.3
Description The issue is related to insufficient protection of sensitive data in the E1 IOT Orchestrator Security component. It allows a low-privileged attacker with network access via HTTP to compromise the JD Edwards EnterpriseOne Orchestrator, resulting in unauthorized access to critical data or complete access to all accessible data.
Recommendations For versions prior to 9.2.8.3, update to version 9.2.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the E1 IOT Orchestrator Security component to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-09195
CVE-2024-21168

Affected Products

Jd Edwards Enterpriseone Orchestrator