CVE-2025-21508

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 21, 2025
Updated: Jan 22, 2025
CWE ID 770

Summary

CVE-2025-21508 is a vulnerability affecting Oracle JD Edwards EnterpriseOne Tools (component: Web Runtime SEC). This issue impacts versions of the software prior to 9.2.9.0. An attacker with low privileges and network access via HTTP can exploit this easily exploitable flaw, resulting in a hang or frequent crashes (complete denial of service) of JD Edwards EnterpriseOne Tools. The Base Score of this vulnerability, according to the Common Vulnerability Scoring System (CVSS), is 6.5, with high impacts on availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle JD Edwards EnterpriseOne Tools

Affected Vendors

  • BonqDAO