CVE-2022-21532: Medium severity oracle jd edwards enterpriseone orchestrator vulnerability
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator). Supported versions that are affected are 9.2.6.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Oracle JD Edwards EnterpriseOne Orchestrator vulnerability?
The vulnerability ID for this Oracle JD Edwards EnterpriseOne Orchestrator vulnerability is CVE-2022-21532.
What is the affected component of this vulnerability?
The affected component of this vulnerability is E1 IOT Orchestrator.
What versions of the JD Edwards EnterpriseOne Orchestrator product are affected by this vulnerability?
Versions 9.2.6.3 and prior of the JD Edwards EnterpriseOne Orchestrator product are affected by this vulnerability.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium with a severity value of 4.3.
How can a low privileged attacker exploit this vulnerability?
A low privileged attacker with network access via HTTP can exploit this vulnerability.