CVE-2025-21552

MEDIUM

Oracle JD Edwards <9.2.9.2 - Unauthorized Access

Title source: llm

Description

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Scores

CVSS v3 6.5
EPSS 0.0040
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-1390
Status published

Affected Products (1)

oracle/jd_edwards_enterpriseone_orchestrator < 9.2.9.2

Timeline

Published Jan 21, 2025
Tracked Since Feb 18, 2026