Unauthenticated Remote Code Execution in JD Edwards EnterpriseOne Tools from Oracle
CVE-2025-21524
9.8CRITICAL
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 January 2025
Summary
A significant vulnerability exists in Oracle's JD Edwards EnterpriseOne Tools, specifically concerning its Monitoring and Diagnostics SEC component. This vulnerability allows an unauthenticated attacker with network access through HTTP to potentially compromise the system. If exploited, attackers can gain control of JD Edwards EnterpriseOne Tools, posing serious risks to data confidentiality, integrity, and availability. The affected versions are those prior to 9.2.9.0. Organizations using this software should review their security posture and apply necessary updates to mitigate risks.
Affected Version(s)
JD Edwards EnterpriseOne Tools * < 9.2.9.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved