Oracle JDEdwards is prone to a remote file disclosure vulnerability in JD Edwards EnterpriseOne Tools.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
An attacker can exploit this issue to view arbitrary files in the context of the affected application. This may aid in further attacks.
Vendor Status:
Orcale had since issued an update for this vulnerability.
Disclosure Timeline:
2012-January-23 Rev 3. Updated JD Edwards information for One World Tools SP24
2012-January-18 Rev 2. Updated credit information
2012-January-17 Rev 1. Initial Release