Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
Published: 2026-06-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JD Edwards EnterpriseOne Tools product contains an unauthenticated vulnerability in the Enterprise Infrastructure Security component that allows attackers to send HTTP requests without credentials. Successful exploitation can lead to unauthorized access to critical data, full data compromise, or the ability to cause a hang or repeated crash, thereby affecting confidentiality and availability. The vulnerability is classified as a high severity flaw with a CVSS v3.1 score of 9.1.

Affected Systems

Affected systems are Oracle JD Edwards EnterpriseOne Tools releases 9.2.0.0 through 9.2.26.2. The vulnerability applies to all builds of JD Edwards EnterpriseOne Tools that include the Enterprise Infrastructure Security component in that version range. No additional affected versions are listed.

Risk and Exploitability

The CVSS score reflects a high likelihood of successful attack, with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/A:H. The EPSS score of less than 1% indicates a low probability that exploitation is currently occurring in the wild, and the vulnerability is not listed in the CISA KEV catalog. Despite this, an unauthenticated attacker with network access can exploit the flaw over HTTP, so organisations should treat this as a high-risk exposure until a patch is applied.

Generated by OpenCVE AI on June 17, 2026 at 19:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for JD Edwards EnterpriseOne Tools that addresses the unauthenticated HTTP access vulnerability.
  • Block external HTTP traffic to the JD Edwards EnterpriseOne Tools interface from untrusted networks or enforce network segmentation.
  • Implement monitoring for abnormal access patterns or crash events on the JD Edwards EnterpriseOne Tools server.

Generated by OpenCVE AI on June 17, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:56:09.498Z

Reserved: 2026-05-18T15:55:10.311Z

Link: CVE-2026-46910

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T00:30:15Z

Weaknesses

No weakness.