Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-06-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools permits an unauthenticated attacker to obtain network access via HTTP and exploit the vulnerability. The primary effect is unauthorized disclosure of critical data, coupled with the ability to insert, update, or delete data that the user does not normally have permission to modify. The underlying weakness is an improper authorization check that allows access to protected resources. The impact affects confidentiality at a high level and integrity at a low-to-moderate level, with the capability to alter or compromise business data within the application.

Affected Systems

Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 through 9.2.26.2 are affected. The vulnerability may also impact additional JD Edwards products that are connected to or shared with the afflicted tool, as the scope of the weakness expands beyond the primary product.

Risk and Exploitability

The CVSS base score of 9.3 signals a critical vulnerability, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is listed as not included in the CISA KEV catalog. It is inferred that an attacker can exploit this weakness by sending crafted HTTP requests to the JD Edwards EnterpriseOne Tools web interface. Because no authentication or privilege is required, the risk to organizations running these supported versions is significant, especially for those with exposed HTTP endpoints to the public or untrusted networks.

Generated by OpenCVE AI on June 17, 2026 at 19:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a version newer than 9.2.26.2 that contains the fix for the Web Runtime Security flaw
  • Reconfigure network interfaces to restrict HTTP access to JD Edwards EnterpriseOne Tools to internal users only, using firewalls or VPNs to limit external exposure
  • Temporarily disable or remove the Web Runtime Security component if it is not essential to business operations, following Oracle guidance for safe operating procedures

Generated by OpenCVE AI on June 17, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:53:22.584Z

Reserved: 2026-05-18T15:55:10.311Z

Link: CVE-2026-46912

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T00:30:15Z

Weaknesses

No weakness.