CVE-2025-21509

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*

History

17 Mar 2025, 19:47

Type Values Removed Values Added
First Time Oracle jd Edwards Enterpriseone Tools
Oracle
CPE cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
References () https://www.oracle.com/security-alerts/cpujan2025.html - () https://www.oracle.com/security-alerts/cpujan2025.html - Vendor Advisory

23 Jan 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en el producto JD Edwards EnterpriseOne Tools de Oracle JD Edwards (componente: Web Runtime SEC). Las versiones compatibles afectadas son anteriores a la 9.2.9.0. Esta vulnerabilidad, que se puede explotar fácilmente, permite que un atacante con pocos privilegios y acceso a la red a través de HTTP ponga en peligro JD Edwards EnterpriseOne Tools. Los ataques exitosos de esta vulnerabilidad pueden dar como resultado la capacidad no autorizada de provocar un bloqueo o un bloqueo repetitivo frecuente (DOS completo) de JD Edwards EnterpriseOne Tools. Puntuación base de CVSS 3.1: 6,5 (impactos en la disponibilidad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
CWE CWE-770

21 Jan 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-21 21:15

Updated : 2025-03-17 19:47


NVD link : CVE-2025-21509

Mitre link : CVE-2025-21509

CVE.ORG link : CVE-2025-21509


JSON object : View

Products Affected

oracle

  • jd_edwards_enterpriseone_tools
CWE
CWE-770

Allocation of Resources Without Limits or Throttling