CVE-2025-21552

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21552 is a vulnerability affecting Oracle JD Edwards' JD Edwards EnterpriseOne Orchestrator, specifically versions before 9.2.9.2. This issue is classified as easily exploitable and allows a low privileged attacker with network access to compromise the JD Edwards EnterpriseOne Orchestrator. Successful attacks can result in unauthorized access to critical data or complete access to all data accessible through the Orchestrator. The Confidentiality impact is rated as High (CVSS Base Score: 6.5) in the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share