Oracle Jd Edwards Enterpriseone Tools vulnerabilities

150 known vulnerabilities affecting oracle/jd_edwards_enterpriseone_tools.

Total CVEs
150
CISA KEV
2
actively exploited
Public exploits
10
Exploited in wild
3
Severity breakdown
CRITICAL18HIGH53MEDIUM77LOW2

Vulnerabilities

Page 8 of 8
CVE-2015-1793MEDIUMCVSS 6.5PoCv9.1v9.22015-07-09
CVE-2015-1793 [MEDIUM] CWE-254 CVE-2015-1793: The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2 The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid lea
nvd
CVE-2014-6565HIGHCVSS 7.5v9.1.52015-01-21
CVE-2014-6565 [HIGH] CVE-2014-6565: Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Produ Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Portal SEC.
nvd
CVE-2011-2321MEDIUMCVSS 4.0v8.982012-01-18
CVE-2011-2321 [MEDIUM] CVE-2011-2321: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDNET).
nvd
CVE-2011-2324MEDIUMCVSS 5.0v8.982012-01-18
CVE-2011-2324 [MEDIUM] CVE-2011-2324: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote attackers to affect availability, related to Enterprise Infrastructure SEC (JDENET).
nvd
CVE-2011-2325MEDIUMCVSS 4.0v8.982012-01-18
CVE-2011-2325 [MEDIUM] CVE-2011-2325: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2326, CVE-2011-3509, and CVE-2011-3524.
nvd
CVE-2011-3524MEDIUMCVSS 4.0v8.982012-01-18
CVE-2011-3524 [MEDIUM] CVE-2011-3524: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2325, CVE-2011-2326, and CVE-2011-3509.
nvd
CVE-2011-3514MEDIUMCVSS 4.0v8.982012-01-18
CVE-2011-3514 [MEDIUM] CVE-2011-3514: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect integrity, related to Enterprise Infrastructure SEC (JDENET).
nvd
CVE-2011-2326MEDIUMCVSS 4.0v8.982012-01-18
CVE-2011-2326 [MEDIUM] CVE-2011-2326: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2325, CVE-2011-3509, and CVE-2011-3524.
nvd
CVE-2011-2317MEDIUMCVSS 4.0v8.982012-01-18
CVE-2011-2317 [MEDIUM] CVE-2011-2317: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect integrity, related to Enterprise Infrastucture SEC (JDNET).
nvd
CVE-2011-3509MEDIUMCVSS 4.0v8.982012-01-18
CVE-2011-3509 [MEDIUM] CVE-2011-3509: Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allow Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2325, CVE-2011-2326, and CVE-2011-3524.
nvd