PT-2025-4274 · Oracle · Jd Edwards Enterpriseone Orchestrator

Published

2025-01-21

·

Updated

2025-06-23

·

CVE-2025-21552

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions JD Edwards EnterpriseOne Orchestrator versions prior to 9.2.9.2
Description The issue is related to insufficient input validation in the E1 IOT Orchestrator Security component. It can be easily exploited by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized access to critical data or complete access to all accessible data.
Recommendations For versions prior to 9.2.9.2, update to version 9.2.9.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the E1 IOT Orchestrator Security component to minimize the risk of exploitation. Avoid using HTTP requests to access sensitive data until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-01287
CVE-2025-21552

Affected Products

Jd Edwards Enterpriseone Orchestrator