#VU103163 Improper input validation in JD Edwards EnterpriseOne Tools - CVE-2025-21511
Published: January 21, 2025
JD Edwards EnterpriseOne Tools
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Web Runtime SEC component in JD Edwards EnterpriseOne Tools. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.