PT-2024-10266 · Oracle · Jd Edwards Enterpriseone Tools

Ahmed Shah

+1

·

Published

2024-12-25

·

Updated

2025-01-22

·

CVE-2025-21507

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions JD Edwards EnterpriseOne Tools versions prior to 9.2.9.0
Description The issue is related to a vulnerability in the Web Runtime SEC component of JD Edwards EnterpriseOne Tools, which can be easily exploited. This vulnerability allows an attacker with low privileges and network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. The vulnerability can result in unauthorized update, insert, or delete access to some of JD Edwards EnterpriseOne Tools' accessible data, as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools' accessible data. The vulnerability is also related to cross-site request forgery.
Recommendations For versions prior to 9.2.9.0, update to version 9.2.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Web Runtime SEC component until a patch is available. Additionally, restrict access to sensitive data and implement measures to prevent cross-site request forgery attacks.

Fix

Race Condition

CSRF

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-00667
CVE-2025-21507

Affected Products

Jd Edwards Enterpriseone Tools