CVE-2024-20905

LOW

Oracle JD Edwards EnterpriseOne Tools < 9.2.8.0 - Authenticated Partial Denial of Service via JDENET

Title source: llm
STIX 2.1

Description

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC). Supported versions that are affected are Prior to 9.2.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

References (1)

Core 1
Core References

Scores

CVSS v3 2.7
EPSS 0.0007
EPSS Percentile 21.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
oracle/jd_edwards_enterpriseone_tools < 9.2.8.0
Published Feb 17, 2024
Tracked Since Feb 18, 2026