Unauthenticated Network Vulnerability in JD Edwards EnterpriseOne Tools by Oracle
CVE-2025-30709
6.1MEDIUM
Summary
The JD Edwards EnterpriseOne Tools product by Oracle has a vulnerability that allows an unauthenticated attacker to compromise its functionality via HTTP. This breach can lead to unauthorized access to sensitive data, including read, update, insert, or deletion capabilities, requiring human interaction to execute. The impact of this vulnerability may extend to additional interconnected products, significantly increasing the risk of data exploitation. Enhanced security measures are critical to mitigate potential threats.
Affected Version(s)
JD Edwards EnterpriseOne Tools 9.2.0.0 <= 9.2.9.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved