Description
Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Oracle JD Edwards (component: Order Promising Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Order Promising. While the vulnerability is in JD Edwards EnterpriseOne Order Promising, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Order Promising. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Order Promising Integration component of Oracle JD Edwards EnterpriseOne. An attacker with only low‑privilege credentials and network connectivity over HTTP can exploit the flaw to take full control of the Order Promising application. The CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H demonstrates that confidentiality, integrity and availability are all compromised, effectively allowing an attacker to execute arbitrary code, modify data, and disrupt service. The scope change indicates that privileges gained may extend beyond the targeted component to other parts of the JD Edwards system.

Affected Systems

The affected product is JD Edwards EnterpriseOne Order Promising, version 9.2. This applies to installations of the Order Promising Integration component in the 9.2 release line.

Risk and Exploitability

The CVSS base score of 9.9 classifies this flaw as Critical. The EPSS score of less than 1% indicates that widespread automated exploitation is unlikely but the presence of a network‑accessible entry point makes targeted attacks feasible. Because the flaw is not listed in the CISA KEV catalog, no active exploits are publicly known, yet the high impact and low effort to exploit warrant immediate attention. The likely attack path is a low‑privilege attacker sending crafted HTTP requests to the vulnerable component and achieving remote code execution.

Generated by OpenCVE AI on June 17, 2026 at 19:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released for JD Edwards EnterpriseOne 9.2 Order Promising that fixes the remote code execution vulnerability.
  • If the patch cannot be applied immediately, isolate the Order Promising service behind a firewall and restrict HTTP access to trusted hosts only.
  • Implement strong authentication and authorization controls for the Order Promising Integration endpoint to prevent low‑privilege users from executing privileged operations.

Generated by OpenCVE AI on June 17, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Oracle JD Edwards (component: Order Promising Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Order Promising. While the vulnerability is in JD Edwards EnterpriseOne Order Promising, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Order Promising. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Order Promising
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_order_promising:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Order Promising
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Order Promising
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:46:28.871Z

Reserved: 2026-05-18T15:55:10.311Z

Link: CVE-2026-46907

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T04:00:02Z

Weaknesses

No weakness.