Impact
Vulnerability exists in the JD Edwards EnterpriseOne Tools component Enterprise Infrastructure Security. An attacker who has logged onto the infrastructure where the tool runs and has low‑privileged local access can compromise the tool, enabling them to perform unauthorized update, insert or delete operations on data available through JD Edwards EnterpriseOne Tools and to trigger a partial denial of service. The flaw is an improper access control weakness (CWE‑284) that impacts integrity and availability but not confidentiality.
Affected Systems
Oracle JD Edwards EnterpriseOne Tools version 9.2.26.3 is the only version listed as affected in the Oracle CPU July 2026 alert. No other versions are mentioned.
Risk and Exploitability
The CVSS base score of 3.6 denotes a low overall risk. The EPSS score of less than 1 % indicates a low likelihood of exploitation in the near term. Exploitation requires local low‑privileged access to the host running the tool, and the vulnerability is not in the CISA KEV catalog, meaning no known active exploits. Accordingly, the overall risk is low, largely confined to environments where low‑privileged local access exists.
OpenCVE Enrichment