CVE-2025-21510

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 21, 2025

Summary

CVE-2025-21510 is a vulnerability affecting the Oracle JD Edwards EnterpriseOne Tools product (Web Runtime SEC component) prior to version 9.2.9.0. This easily exploitable issue permits unauthenticated attackers with network access via HTTP to compromise the JD Edwards EnterpriseOne Tools. A successful exploit could result in unauthorized access to critical data or complete control over all accessible data. The Confidentiality impact is rated High (CVSS Base Score: 7.5). Attackers can leverage this vulnerability to gain sensitive information, potentially leading to significant business consequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle JD Edwards EnterpriseOne Tools

Affected Vendors

  • BonqDAO