Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-07-21
Score: 3.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability exists in the JD Edwards EnterpriseOne Tools component Enterprise Infrastructure Security. An attacker who has logged onto the infrastructure where the tool runs and has low‑privileged local access can compromise the tool, enabling them to perform unauthorized update, insert or delete operations on data available through JD Edwards EnterpriseOne Tools and to trigger a partial denial of service. The flaw is an improper access control weakness (CWE‑284) that impacts integrity and availability but not confidentiality.

Affected Systems

Oracle JD Edwards EnterpriseOne Tools version 9.2.26.3 is the only version listed as affected in the Oracle CPU July 2026 alert. No other versions are mentioned.

Risk and Exploitability

The CVSS base score of 3.6 denotes a low overall risk. The EPSS score of less than 1 % indicates a low likelihood of exploitation in the near term. Exploitation requires local low‑privileged access to the host running the tool, and the vulnerability is not in the CISA KEV catalog, meaning no known active exploits. Accordingly, the overall risk is low, largely confined to environments where low‑privileged local access exists.

Generated by OpenCVE AI on August 4, 2026 at 04:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch for JD Edwards EnterpriseOne Tools released in Oracle CPU July 2026
  • Enforce least privilege for users accessing JD Edwards EnterpriseOne Tools
  • Enable detailed logging and monitor for unauthorized update or delete actions

Generated by OpenCVE AI on August 4, 2026 at 04:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle JD Edwards EnterpriseOne Tools Allows Unauthorized Data Modifications and Partial Denial of Service

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle JD Edwards EnterpriseOne Tools Allows Unauthorized Data Modifications and Partial Denial of Service

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification and Partial Denial of Service in JD Edwards EnterpriseOne Tools

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification and Partial Denial of Service in JD Edwards EnterpriseOne Tools
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 3.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.26.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T10:56:11.581Z

Reserved: 2026-07-08T15:51:40.531Z

Link: CVE-2026-60347

cve-icon Vulnrichment

Updated: 2026-07-27T10:56:03.840Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses