CVE-2020-9546 | Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.4 E1 IOT Orchestrator Security deserialization (Nessus ID 216682)
A vulnerability marked as very critical has been reported in Oracle JD Edwards EnterpriseOne Orchestrator up to 9.2.4. The affected element is an unknown function of the component E1 IOT Orchestrator Security. The manipulation leads to deserialization.
This vulnerability is documented as CVE-2020-9546. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.