CVE-2011-0836 describes an unspecified integrity vulnerability within Oracle JD Edwards EnterpriseOne Tools (versions 8.9 GA through 8.98.4.1) and OneWorld Tools (through 24.1.3), specifically related to the Web Runtime SEC component. This vulnerability has a CVSS score of 3.5, indicating a low severity, and requires remote authenticated access with medium attack complexity to achieve a partial integrity impact. While there is no evidence of active exploitation or KEV listing, multiple Cross-Site Scripting (XSS) exploits are publicly available on ExploitDB, demonstrating potential attack vectors. Despite the available exploit code, the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.9CPE matchmatch criteria | cpe:2.3:a:oracle:enterpriseone_tools:8.9:*:*:*:*:*:*:* | ||
8.9CPE matchmatch criteria | cpe:2.3:a:oracle:jd_edwards_enterpriseone:8.9:budle14:*:*:*:*:*:* | ||
8.9CPE matchmatch criteria | cpe:2.3:a:oracle:jd_edwards_enterpriseone:8.9:bundle14:*:*:*:*:*:* | ||
8.9CPE matchmatch criteria | cpe:2.3:a:oracle:jd_edwards_enterpriseone:8.9:bundle21:*:*:*:*:*:* | ||
8.9CPE matchmatch criteria | cpe:2.3:a:oracle:jd_edwards_enterpriseone:8.9:bundle9:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.