Unauthorized Access in JD Edwards EnterpriseOne Orchestrator by Oracle
CVE-2021-2052
5.8MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 January 2021
Summary
The vulnerability in Oracle's JD Edwards EnterpriseOne Orchestrator allows an unauthenticated attacker with network access via HTTP to gain unauthorized read access to sensitive data. This flaw primarily affects the orchestrator component, but its exploitation could impact other interconnected products within the JD Edwards ecosystem. To mitigate the risk, it is crucial that users update to version 9.2.5.1 or later to close this security gap.
Affected Version(s)
JD Edwards EnterpriseOne Orchestrator < 9.2.5.1
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved