PT-2024-10307 · Oracle · Jd Edwards Enterpriseone Tools
Ahmed Shah
+2
·
Published
2024-12-25
·
Updated
2025-01-23
·
CVE-2025-21512
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JD Edwards EnterpriseOne Tools versions prior to 9.2.9.0
Description
The issue is related to the use of open redirection in the Web Runtime SEC component of JD Edwards EnterpriseOne Tools. This allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful attacks require human interaction and can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data.
Recommendations
For versions prior to 9.2.9.0, update to version 9.2.9.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the Web Runtime SEC component until a patch is available.
Avoid using HTTP for network access until the issue is resolved.
Restrict human interaction with the system to minimize the risk of exploitation.
Fix
Improper Authentication
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jd Edwards Enterpriseone Tools