By exploiting this vulnerability, an unauthenticated attacker would be able to remotely shutdown the JD Edwards server. This would result in the total unavailability of the ERP functionality, preventing company users from performing the required business processes.
If a specially-crafted message is sent to the JDENET Service, the JDENET Kernel performs a shutdown of the service.
Further technical details about this issue are not disclosed at this moment with the purpose of providing enough time to affected customers to patch their systems and protect against the exploitation of the described vulnerability.
Disclosure Timeline:
2010-09-20: Vulnerability information to Oracle.
2010-09-21: Oracle confirms reception of vulnerability submission.
2010-09-24: Oracle states vulnerability is under investigation.
2010-10-07: Oracle confirms vulnerability.
2011-04-19: Oracle releases fixes in CPU.
2011-04-27: Security advisory released.