cbcvebase.

Oracle Jd Edwards Enterpriseone Tools vulnerabilities

150 known vulnerabilities affecting oracle/jd_edwards_enterpriseone_tools.

Total CVEs
150
CISA KEV
2
actively exploited
Public exploits
11
Exploited in wild
6
Severity breakdown
CRITICAL18HIGH53MEDIUM77LOW2

Vulnerabilities

Page 7 of 8
CVE-2022-21630P4MEDIUMCVSS 6.1≤ 9.2.6.42022-10-18
CVE-2022-21630 [MEDIUM] CVE-2022-21630: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.6.4 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction fro
nvd
CVE-2023-22055P4MEDIUMCVSS 6.1fixed in 9.2.7.42023-07-18
CVE-2023-22055 [MEDIUM] CVE-2023-22055: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from
nvd
CVE-2021-32809P4MEDIUMCVSS 5.4fixed in 9.2.6.02021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2018-2659P4MEDIUMCVSS 6.1v9.22018-01-18
CVE-2018-2659 [MEDIUM] CVE-2018-2659: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from
nvd
CVE-2018-2658P4MEDIUMCVSS 6.1v9.22018-01-18
CVE-2018-2658 [MEDIUM] CVE-2018-2658: Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomp Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from
nvd
CVE-2021-32808P4MEDIUMCVSS 5.4≤ 9.2.6.02021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
nvd
CVE-2025-21586P4MEDIUMCVSS 5.4≥ 9.2.0.0, ≤ 9.2.9.22025-04-15
CVE-2025-21586 [MEDIUM] CWE-284 CVE-2025-21586: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interactio
nvd
CVE-2024-21245P4MEDIUMCVSS 5.4fixed in 9.2.9.02025-01-21
CVE-2024-21245 [MEDIUM] CWE-346 CVE-2024-21245: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Busines Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human
nvd
CVE-2020-27193P4MEDIUMCVSS 6.1fixed in 9.2.6.02020-11-12
CVE-2020-27193 [MEDIUM] CWE-79 CVE-2020-27193: A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows rem A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
nvd
CVE-2021-37695P4MEDIUMCVSS 5.4fixed in 9.2.6.02021-08-13
CVE-2021-37695 [MEDIUM] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdi
nvd
CVE-2021-2373P4MEDIUMCVSS 5.4≥ 9.2.0.0, ≤ 9.2.5.32021-07-21
CVE-2021-2373 [MEDIUM] CVE-2021-2373: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime). Supported versions that are affected are 9.2.5.3 and Prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a per
nvd
CVE-2022-21629P4MEDIUMCVSS 5.4≤ 9.2.6.42022-10-18
CVE-2022-21629 [MEDIUM] CVE-2022-21629: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.6.4 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from
nvd
CVE-2023-21936P4MEDIUMCVSS 5.4fixed in 9.2.7.32023-04-18
CVE-2023-21936 [MEDIUM] CVE-2023-21936: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from
nvd
CVE-2025-21507P4MEDIUMCVSS 5.4fixed in 9.2.9.02025-01-21
CVE-2025-21507 [MEDIUM] CWE-352 CVE-2025-21507: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interacti
nvd
CVE-2021-20227P4MEDIUMCVSS 5.5fixed in 9.2.6.02021-03-23
CVE-2021-20227 [MEDIUM] CWE-416 CVE-2021-20227: A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
nvd
CVE-2018-11055P4MEDIUMCVSS 5.5v9.22018-08-31
CVE-2018-11055 [MEDIUM] CWE-404 CVE-2018-11055: RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauth
nvd
CVE-2011-2324P4MEDIUMCVSS 5.0v8.982012-01-18
CVE-2011-2324 [MEDIUM] CVE-2011-2324: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote attackers to affect availability, related to Enterprise Infrastructure SEC (JDENET).
nvd
CVE-2025-21517P4MEDIUMCVSS 4.3fixed in 9.2.9.02025-01-21
CVE-2025-21517 [MEDIUM] CWE-863 CVE-2025-21517: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Run Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability c
nvd
CVE-2024-20937P4MEDIUMCVSS 4.3fixed in 9.2.8.12024-02-17
CVE-2024-20937 [MEDIUM] CWE-200 CVE-2024-20937: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitor Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported versions that are affected are Prior to 9.2.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this
nvd
CVE-2023-21927P4MEDIUMCVSS 4.3fixed in 9.2.7.32023-04-18
CVE-2023-21927 [MEDIUM] CVE-2023-21927: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interop Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can
nvd
Oracle Jd Edwards Enterpriseone Tools vulnerabilities | cvebase