CVE-2025-21511

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 21, 2025

Summary

CVE-2025-21511 is a vulnerability affecting Oracle JD Edwards EnterpriseOne Tools (component: Web Runtime SEC) prior to version 9.2.9.0. This easily exploitable issue allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. The CVSS Base Score is 7.5 for Confidentiality impacts, making this a significant vulnerability. The attack vector is remote, requiring no authentication (AV:N), and the attack complexity is low (AC:L), making this a potential threat for organizations using the affected versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle JD Edwards EnterpriseOne Tools

Affected Vendors

  • BonqDAO