Unauthorized Access in JD Edwards EnterpriseOne Orchestrator by Oracle
CVE-2021-2052

5.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 January 2021

Summary

The vulnerability in Oracle's JD Edwards EnterpriseOne Orchestrator allows an unauthenticated attacker with network access via HTTP to gain unauthorized read access to sensitive data. This flaw primarily affects the orchestrator component, but its exploitation could impact other interconnected products within the JD Edwards ecosystem. To mitigate the risk, it is crucial that users update to version 9.2.5.1 or later to close this security gap.

Affected Version(s)

JD Edwards EnterpriseOne Orchestrator < 9.2.5.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.