Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOracle Jd Edwards Enterpriseone Tools
APPOracle9.2.0.0 – 9.2.26.4
Powiązane podatności
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)
Krytyczna podatność w Oracle JD Edwards EnterpriseOne Tools — przejęcie systemu
Krytyczne pominięcie uwierzytelnienia w Oracle JD Edwards EnterpriseOne Tools
Obejście uwierzytelnienia w Oracle JD Edwards EnterpriseOne Tools
Krytyczna podatność w Oracle JD Edwards EnterpriseOne Tools — przejęcie kontroli