PT-2025-4244 · Oracle · Jd Edwards Enterpriseone Tools

Ahmed Shah

+1

·

Published

2025-01-21

·

Updated

2025-01-31

·

CVE-2025-21515

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JD Edwards EnterpriseOne Tools versions prior to 9.2.9.0
Description The issue is related to a lack of authentication for a critical function in the Web Runtime SEC component of JD Edwards EnterpriseOne Tools. This can be exploited by a remote attacker using a specially crafted HTTP request, potentially impacting the confidentiality, integrity, and availability of protected information. Successful attacks can result in the takeover of JD Edwards EnterpriseOne Tools.
Recommendations For versions prior to 9.2.9.0, update to version 9.2.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Web Runtime SEC component to minimize the risk of exploitation. Additionally, limit network access via HTTP to reduce the attack surface.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01224
CVE-2025-21515

Affected Products

Jd Edwards Enterpriseone Tools