CyberRota Analysis
AI-GeneratedA vulnerability exists in the JD Edwards EnterpriseOne Configurator component of Oracle JD Edwards version 9.2, allowing low-privileged attackers with network access via HTTP to exploit it. Successful exploitation can lead to denial of service, unauthorized data manipulation, and limited data exposure, affecting the confidentiality, integrity, and availability of the system. Organizations using this version of JD Edwards should prioritize remediation to mitigate potential disruptions and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Configurator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Configurator as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Configurator accessible data and unauthorized read access to a subset of JD Edwards EnterpriseOne Configurator accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H).
Related CVEs
Other vulnerabilities affecting the same vendor(s)