CVE-2016-0423
Summary
| CVE | CVE-2016-0423 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-01-21 02:59:32 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1 and 9.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Enterprise Infrastructure SEC. |
Risk And Classification
Primary CVSS: v2.0 7.3 from [email protected]
AV:N/AC:H/Au:N/C:C/I:C/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
PartialAV:N/AC:H/Au:N/C:C/I:C/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Jd Edwards Products | 9.1 | All | All | All |
| Application | Oracle | Jd Edwards Products | 9.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle JD Edwards EnterpriseOne Multiple Bugs Let Remote Users Access and Modify Data and Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| JD Edwards JDENET End of File DoS | Onapsis | af854a3a-2127-422b-91ae-364da2661108 | www.onapsis.com | |
| JD Edwards 9.1 EnterpriseOne Server JDENET Denial Of Service ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| Oracle Critical Patch Update - January 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Vendor Advisory |
| Full Disclosure: Onapsis Security Advisory ONAPSIS-2016-014: JD Edwards JDENET function DoS | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.