JD Edwards is an enterprise resource planning vendor with a narrow product footprint centered on its EnterpriseOne and OneWorld platforms, which serve large organizations for financial and operational management. Vulnerabilities affecting this vendor's products show a durable signal around memory-safety and information-disclosure weaknesses, including NULL pointer dereferences and cases where insufficient detail in disclosures themselves complicates vulnerability assessment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jdedwards over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1967HIGH Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand | Apr 21, 2020 | 7.5 | 51 | NO | NO |
CVE-2006-1884HIGH Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# | Apr 20, 2006 | 10.0 | 26 | NO | NO |
CVE-2005-3465HIGH Unspecified vulnerability in JDEdwards HTML Server in Oracle EnterpriseOne 8.94 OneWorld XE up to 8.95_B1, 8.94_Q1, and SP23_K1 has unknown impact and attack vectors, as identified | Nov 2, 2005 | 10.0 | 26 | NO | NO |
CVE-2008-1828HIGH Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.19, 8.48.16, and 8.49.09 has unknown impact and | Apr 16, 2008 | 9.0 | 23 | NO | NO |
CVE-2008-1830HIGH Unspecified vulnerability in the PeopleSoft HCM ePerformance component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 and 9.0 has unknown impact and remote attack | Apr 16, 2008 | 9.0 | 22 | NO | NO |
CVE-2008-4000MEDIUM Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidenti | Oct 14, 2008 | 6.4 | 18 | NO | NO |
CVE-2008-5452MEDIUM Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 allows remote authenticated users to affec | Jan 14, 2009 | 5.5 | 16 | NO | NO |
CVE-2008-5455MEDIUM Unspecified vulnerability in the PeopleSoft Enterprise HRMS - ePerformance component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 allows remote authenticated | Jan 14, 2009 | 4.9 | 15 | NO | NO |
CVE-2008-5451MEDIUM Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.97.2.5 allows remote authenticated users to affect confid | Jan 14, 2009 | 4.0 | 14 | NO | NO |
Unspecified vulnerability in the JDE EnterpriseOne Business Service Server component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.97.2.2 and 8.98.0.1 allows local | Oct 14, 2008 | 3.2 | 12 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jdedwards.
Media articles that mention a CVE ID that affects a product developed by Jdedwards — matched by CVE ID, not by vendor name.