Unauthorized Access in JD Edwards EnterpriseOne Orchestrator by Oracle
CVE-2021-2052
5.8MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2021
What is CVE-2021-2052?
The vulnerability in Oracle's JD Edwards EnterpriseOne Orchestrator allows an unauthenticated attacker with network access via HTTP to gain unauthorized read access to sensitive data. This flaw primarily affects the orchestrator component, but its exploitation could impact other interconnected products within the JD Edwards ecosystem. To mitigate the risk, it is crucial that users update to version 9.2.5.1 or later to close this security gap.
Affected Version(s)
JD Edwards EnterpriseOne Orchestrator < 9.2.5.1