CVE-2025-21513

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21513 is a vulnerability affecting the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (Web Runtime SEC component). Affected versions are prior to 9.2.9.0. This easily exploitable issue enables unauthenticated attackers with network access via HTTP to compromise JD Edwards EnterpriseOne Tools, resulting in unauthorized update, insert, or delete access to some data, and unauthorized read access to a subset of data. While the initial impact is on JD Edwards EnterpriseOne Tools, subsequent effects may influence additional products. The CVSS Base Score is 6.1, with Confidentiality and Integrity impacts. (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle JD Edwards EnterpriseOne Tools

Affected Vendors

  • BonqDAO