Oracle Jd Edwards Enterpriseone Tools vulnerabilities
150 known vulnerabilities affecting oracle/jd_edwards_enterpriseone_tools.
Total CVEs
150
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL18HIGH53MEDIUM77LOW2
Vulnerabilities
Page 6 of 8
CVE-2021-26271P4MEDIUMCVSS 6.5fixed in 9.2.6.02021-01-26
CVE-2021-26271 [MEDIUM] CWE-829 CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
nvd
CVE-2017-15707P4MEDIUMCVSS 6.2v9.22017-12-01
CVE-2017-15707 [MEDIUM] CWE-20 CVE-2017-15707: In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulne
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
nvd
CVE-2018-3006P4MEDIUMCVSS 6.1v9.22018-07-18
CVE-2018-3006 [MEDIUM] CVE-2018-3006: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a p
nvd
CVE-2018-2945P4MEDIUMCVSS 6.1v9.22018-07-18
CVE-2018-2945 [MEDIUM] CVE-2018-2945: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a p
nvd
CVE-2018-2950P4MEDIUMCVSS 6.1v9.22018-07-18
CVE-2018-2950 [MEDIUM] CVE-2018-2950: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a p
nvd
CVE-2018-2948P4MEDIUMCVSS 6.1v9.22018-07-18
CVE-2018-2948 [MEDIUM] CVE-2018-2948: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a p
nvd
CVE-2018-2999P4MEDIUMCVSS 6.1v9.22018-07-18
CVE-2018-2999 [MEDIUM] CVE-2018-2999: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a p
nvd
CVE-2018-2946P4MEDIUMCVSS 6.1v9.22018-07-18
CVE-2018-2946 [MEDIUM] CVE-2018-2946: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a p
nvd
CVE-2025-30709P4MEDIUMCVSS 6.1≥ 9.2.0.0, ≤ 9.2.9.22025-04-15
CVE-2025-30709 [MEDIUM] CWE-284 CVE-2025-30709: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interacti
nvd
CVE-2025-21512P4MEDIUMCVSS 6.1fixed in 9.2.9.02025-01-21
CVE-2025-21512 [MEDIUM] CWE-601 CVE-2025-21512: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interact
nvd
CVE-2025-21527P4MEDIUMCVSS 6.1fixed in 9.2.9.02025-01-21
CVE-2025-21527 [MEDIUM] CWE-862 CVE-2025-21527: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interact
nvd
CVE-2024-21150P4MEDIUMCVSS 6.1fixed in 9.2.8.22024-07-16
CVE-2024-21150 [MEDIUM] CWE-284 CVE-2024-21150: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interact
nvd
CVE-2025-21513P4MEDIUMCVSS 6.1fixed in 9.2.9.02025-01-21
CVE-2025-21513 [MEDIUM] CWE-352 CVE-2025-21513: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interact
nvd
CVE-2025-21538P4MEDIUMCVSS 6.1fixed in 9.2.9.22025-01-21
CVE-2025-21538 [MEDIUM] CWE-352 CVE-2025-21538: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interact
nvd
CVE-2025-21514P4MEDIUMCVSS 5.3fixed in 9.2.9.02025-01-21
CVE-2025-21514 [MEDIUM] CWE-862 CVE-2025-21514: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability
nvd
CVE-2020-9281P4MEDIUMCVSS 6.1fixed in 9.2.5.22020-03-07
CVE-2020-9281 [MEDIUM] CWE-79 CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 a
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
nvd
CVE-2018-2949P4MEDIUMCVSS 6.1v9.22018-07-18
CVE-2018-2949 [MEDIUM] CVE-2018-2949: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a p
nvd
CVE-2021-2375P4MEDIUMCVSS 6.1≥ 9.2.0.0, ≤ 9.2.5.32021-07-21
CVE-2021-2375 [MEDIUM] CVE-2021-2375: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.5.3 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a pe
nvd
CVE-2022-21409P4MEDIUMCVSS 6.1fixed in 9.2.6.32022-04-19
CVE-2022-21409 [MEDIUM] CVE-2022-21409: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a
nvd
CVE-2022-21631P4MEDIUMCVSS 6.1≤ 9.2.6.42022-10-18
CVE-2022-21631 [MEDIUM] CWE-79 CVE-2022-21631: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC). Supported versions that are affected are 9.2.6.4 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interact
nvd