Input validation error in JD Edwards EnterpriseOne Tools - CVE-2014-6565

 

Input validation error in JD Edwards EnterpriseOne Tools - CVE-2014-6565

Published: January 21, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40934
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-6565
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Portal SEC.


Affected software

JD Edwards EnterpriseOne Tools

How to mitigate CVE-2014-6565

Install update from vendor's website.


External References

Related Security Bulletins