Oracle Jd Edwards Enterpriseone Tools vulnerabilities
150 known vulnerabilities affecting oracle/jd_edwards_enterpriseone_tools.
Total CVEs
150
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL18HIGH53MEDIUM77LOW2
Vulnerabilities
Page 5 of 8
CVE-2018-11054P3HIGHCVSS 7.5v9.22018-08-31
CVE-2018-11054 [HIGH] CWE-190 CVE-2018-11054: RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote a
RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service.
nvd
CVE-2021-21409P3MEDIUMCVSS 5.9fixed in 9.2.6.32021-03-30
CVE-2021-21409 [MEDIUM] CWE-444 CVE-2021-21409: Netty is an open-source, asynchronous event-driven network application framework for rapid developme
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the requ
nvd
CVE-2018-2947P3MEDIUMCVSS 6.5v9.22018-07-18
CVE-2018-2947 [MEDIUM] CVE-2018-2947: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in
nvd
CVE-2021-41183P3MEDIUMCVSS 6.1≤ 9.2.6.32021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2021-22939P4MEDIUMCVSS 5.3≤ 9.2.6.12021-08-16
CVE-2021-22939 [MEDIUM] CWE-295 CVE-2021-22939: If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthori
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
nvd
CVE-2020-1971P3MEDIUMCVSS 5.9fixed in 9.2.5.32020-12-08
CVE-2020-1971 [MEDIUM] CWE-476 CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A
nvd
CVE-2020-28500P3MEDIUMCVSS 5.3fixed in 9.2.6.12021-02-15
CVE-2020-28500 [MEDIUM] CVE-2020-28500: Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
nvd
CVE-2021-31799P3HIGHCVSS 7.0fixed in 9.2.6.12021-07-30
CVE-2021-31799 [HIGH] CWE-78 CVE-2021-31799: In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to exe
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
nvd
CVE-2021-4160P4MEDIUMCVSS 5.9v9.2.6.32022-01-28
CVE-2021-4160 [MEDIUM] CVE-2021-4160: There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are
There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including some of the TLS 1.3 default curves. Impact was not analyzed in detail, because the pre-requisites for attack are considered unlikely and include reusing private keys. Analysis suggests that attacks against RSA and DSA as a result of this de
nvd
CVE-2025-21509P4MEDIUMCVSS 6.5fixed in 9.2.9.02025-01-21
CVE-2025-21509 [MEDIUM] CWE-770 CVE-2025-21509: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability c
nvd
CVE-2025-21508P4MEDIUMCVSS 6.5fixed in 9.2.9.02025-01-21
CVE-2025-21508 [MEDIUM] CWE-770 CVE-2025-21508: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability c
nvd
CVE-2018-11056P4MEDIUMCVSS 6.5v9.22018-08-31
CVE-2018-11056 [MEDIUM] CWE-400 CVE-2018-11056: RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition ver
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially caus
nvd
CVE-2021-31810P4MEDIUMCVSS 5.8fixed in 9.2.6.12021-07-13
CVE-2021-31810 [MEDIUM] CVE-2021-31810: An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicio
An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes curl extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port sca
nvd
CVE-2017-3517P4MEDIUMCVSS 6.5v9.22017-04-24
CVE-2017-3517 [MEDIUM] CVE-2017-3517: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can re
nvd
CVE-2018-11057P4MEDIUMCVSS 5.9v9.22018-08-31
CVE-2018-11057 [MEDIUM] CWE-327 CVE-2018-11057: RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) c
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
nvd
CVE-2021-26272P4MEDIUMCVSS 6.5fixed in 9.2.6.02021-01-26
CVE-2021-26272 [MEDIUM] CWE-829 CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
nvd
CVE-2025-53060P4MEDIUMCVSS 6.1≥ 9.2.0.0, ≤ 9.2.9.42025-10-21
CVE-2025-53060 [MEDIUM] CWE-284 CVE-2025-53060: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interacti
nvd
CVE-2025-53056P4MEDIUMCVSS 6.1≥ 9.2.0.0, ≤ 9.2.9.42025-10-21
CVE-2025-53056 [MEDIUM] CWE-285 CVE-2025-53056: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Object and Environment Tech). Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require huma
nvd
CVE-2026-21946P4MEDIUMCVSS 6.1≥ 9.2.0.0, ≤ 9.2.26.02026-01-20
CVE-2026-21946 [MEDIUM] CWE-79 CVE-2026-21946: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interacti
nvd
CVE-2025-30760P4MEDIUMCVSS 5.4≥ 9.2.0.0, ≤ 9.2.9.32025-07-15
CVE-2025-30760 [MEDIUM] CWE-284 CVE-2025-30760: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability ca
nvd