CVE-2022-21409
published 2022-04-19CVE-2022-21409: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). The supported version that is affected is Prior to…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.80%
52.6th percentile
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.3 | 9.2.6.3 |
| oracle_corporation | jd_edwards_enterpriseone_tools | >= unspecified < 9.2.6.3 | 9.2.6.3 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_oracle6.1MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle JD Edwards Risk Matrix: Web Runtime — CVE-2022-21409
vendor_oracle·2022-04-15·CVSS 6.1
CVE-2022-21409 [MEDIUM] Oracle Oracle JD Edwards Risk Matrix: Web Runtime — CVE-2022-21409
Oracle Oracle JD Edwards Risk Matrix: Web Runtime vulnerability
CVE: CVE-2022-21409
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Netty) — CVE-2021-21409
vendor_oracle·2022-04-15·CVSS 5.9
CVE-2021-21409 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (Netty) — CVE-2021-21409
Oracle Oracle Communications Risk Matrix: Policy (Netty) vulnerability
CVE: CVE-2021-21409
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
origin-aggregated-logging/elasticsearch: Incomplete fix for netty-codec-http CVE-2021-21409
vendor_redhat·2022-02-28·CVSS 5.9
CVE-2022-0552 [MEDIUM] CWE-444 origin-aggregated-logging/elasticsearch: Incomplete fix for netty-codec-http CVE-2021-21409
origin-aggregated-logging/elasticsearch: Incomplete fix for netty-codec-http CVE-2021-21409
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.
A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content.
Statement: This CVE only applies to the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container image, shipped in OpenShi
Oracle
Oracle Oracle NoSQL Database Risk Matrix: Administration (Netty) — CVE-2021-21409
vendor_oracle·2022-01-15·CVSS 5.5
CVE-2021-21409 [MEDIUM] Oracle Oracle NoSQL Database Risk Matrix: Administration (Netty) — CVE-2021-21409
Oracle Oracle NoSQL Database Risk Matrix: Administration (Netty) vulnerability
CVE: CVE-2021-21409
CVSS: 5.5
Protocol: Local Logon
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
GHSA
GHSA-qjmw-83pw-2r28: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime)
ghsa_unreviewed·2022-04-20
CVE-2022-21409 [MEDIUM] GHSA-qjmw-83pw-2r28: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime)
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Scor
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-19
Published