Web Runtime Security Flaw in JD Edwards EnterpriseOne by Oracle
CVE-2025-30740
6.5MEDIUM
What is CVE-2025-30740?
A vulnerability has been identified in Oracle's JD Edwards EnterpriseOne Tools, particularly affecting the Web Runtime Security component. This flaw can be exploited by attackers with low privileges and network access via HTTP, enabling them to gain unauthorized access to sensitive data. Once compromised, the attacker may obtain full access to all data within the JD Edwards EnterpriseOne Tools environment, posing significant risks to organizations relying on this software for business operations.
Affected Version(s)
JD Edwards EnterpriseOne Tools 9.2.0.0 <= 9.2.9.2