Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability resides in the Interoperability Security component of JD Edwards EnterpriseOne Tools, specifically within the JDENET network interface. The flaw allows an unauthenticated attacker who can reach JDENET to compromise the tool, which may result in a partial loss of availability for JD Edwards services. The CVSS v3.1 base score of 3.7 indicates a low severity classification, pointing to a modest impact on availability only, as suggested by the SeV vector AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L.

Affected Systems

Oracle JD Edwards EnterpriseOne Tools, version 9.2.26.3.

Risk and Exploitability

The EPSS score of less than 1% signals a low probability of active exploitation, and the vulnerability is not current in the CISA KEV catalog. Exploitation requires only network access to JDENET; no user privileges or local access are necessary. Attack complexity is high, making it difficult to execute, but the low overall vulnerability score reflects only a limited availability impact.

Generated by OpenCVE AI on August 4, 2026 at 04:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s issued patch or upgrade to a newer version than 9.2.26.3
  • Restrict JDENET access by configuring firewalls or routing to allow only trusted hosts and networks
  • Continuously monitor JDENET traffic for anomalous connections and watch JD Edwards performance for signs of partial outages

Generated by OpenCVE AI on August 4, 2026 at 04:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Partial Denial of Service via JDENET in JD Edwards EnterpriseOne Tools
Weaknesses CWE-306

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Partial Denial of Service via JDENET in JD Edwards EnterpriseOne Tools
Weaknesses CWE-306

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.26.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T10:55:12.871Z

Reserved: 2026-07-08T15:51:40.531Z

Link: CVE-2026-60346

cve-icon Vulnrichment

Updated: 2026-07-27T10:55:09.004Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses