CVE-2025-21508
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 770
Summary
CVE-2025-21508 is a vulnerability affecting Oracle JD Edwards EnterpriseOne Tools (component: Web Runtime SEC). This issue impacts versions of the software prior to 9.2.9.0. An attacker with low privileges and network access via HTTP can exploit this easily exploitable flaw, resulting in a hang or frequent crashes (complete denial of service) of JD Edwards EnterpriseOne Tools. The Base Score of this vulnerability, according to the Common Vulnerability Scoring System (CVSS), is 6.5, with high impacts on availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle JD Edwards EnterpriseOne Tools
Affected Vendors
- BonqDAO