PT-2024-10267 · Oracle · Jd Edwards Enterpriseone Tools
Published
2024-12-25
·
Updated
2025-01-22
·
CVE-2025-21517
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JD Edwards EnterpriseOne Tools versions prior to 9.2.9.0
Description
The issue is related to a vulnerability in the Web Runtime SEC component of JD Edwards EnterpriseOne Tools, which can be exploited by a low-privileged attacker with network access via HTTP. This vulnerability allows unauthorized update, insert, or delete access to some of JD Edwards EnterpriseOne Tools' accessible data. The vulnerability is associated with weaknesses in the authorization mechanism, potentially enabling a remote attacker to read, modify, and delete files.
Recommendations
For versions prior to 9.2.9.0, update to version 9.2.9.0 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Fix
Incorrect Authorization
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jd Edwards Enterpriseone Tools