Oracle JD Edwards EnterpriseOne Tools Vulnerability in Web Runtime
CVE-2018-2950
What is CVE-2018-2950?
A vulnerability exists in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products, specifically in the Web Runtime subcomponent. This security flaw allows unauthenticated attackers with network access via HTTP to manipulate JD Edwards EnterpriseOne Tools. Successful exploitation requires human interaction from an individual who is not the attacker, which poses a unique challenge for mitigation. Although the primary security lapse is within JD Edwards EnterpriseOne Tools, the repercussions of successful attacks may extend to other connected products. Offenders can gain unauthorized access leading to potential updates, inserts, or deletions of accessible data, as well as obtaining unauthorized read access to certain datasets within JD Edwards EnterpriseOne Tools.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
JD Edwards EnterpriseOne Tools 9.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved