CVE-2021-2373 is a medium-severity vulnerability affecting Oracle JD Edwards EnterpriseOne Tools versions 9.2.5.3 and prior, specifically within the Web Runtime component. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system, requiring user interaction to succeed. Successful exploitation can lead to unauthorized read, update, insert, or delete access to a subset of the tool's data, impacting confidentiality and integrity. While no public exploits, Metasploit modules, or Nuclei templates are available, and there is minimal community discussion or media coverage, organizations using affected versions should prioritize patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.2.0.0, <= 9.2.5.3CPE matchmatch criteria | cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.