SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-2325

Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2326,…

MEDIUM 4.0EPSS 0.91%

Does this matter?

Lower severity and a low EPSS score (0.91%). Track it; it rarely justifies an emergency change on its own.

Description

Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2326, CVE-2011-3509, and CVE-2011-3524.

CVSS 2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
0.91% probability · 58th percentile
CISA KEV
Not listed
Affected
oracle/jd edwards enterpriseone tools · oracle/jd edwards products
Source
secalert_us@oracle.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.