Description
Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne CRM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle JD Edwards EnterpriseOne CRM Foundation version 9.2 contains a flaw that permits a low‑privileged attacker with network access to compromise the application. The vulnerability is easily exploitable and can lead to full compromise of confidentiality, integrity, and availability. The weakness is linked to improper access control, authentication bypass, and missing authentication, as indicated by the CWE identifiers.

Affected Systems

The only affected release is JD Edwards EnterpriseOne CRM Foundation 9.2 from Oracle Corporation. Systems running this version expose an HTTP interface that is reachable over the network and are therefore susceptible to the described flaw.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 score of 8.8, indicating high severity for confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests that exploitation is currently uncommon, and the issue is not listed in the CISA KEV catalogue. Based on the description, the likely attack vector is a network‑based HTTP request. An attacker with low privileges—either weak authenticated access or potentially no authentication—could trigger the exploit by sending a crafted request, requiring only basic network connectivity.

Generated by OpenCVE AI on August 2, 2026 at 22:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CVE‑2026‑60489 CPU patch for JD Edwards EnterpriseOne CRM Foundation 9.2 released in July 2026.
  • Restrict inbound network traffic to the CRM Foundation HTTP interface by applying firewall rules or network segmentation to allow traffic only from trusted sources.
  • Enforce multi‑factor authentication, role‑based access controls, and least‑privilege principles for all users that can access the CRM Foundation.
  • If a patch is not yet available, block or monitor HTTP traffic to the vulnerable endpoints to mitigate potential exploitation.

Generated by OpenCVE AI on August 2, 2026 at 22:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Easily Exploitable Vulnerability in JD Edwards EnterpriseOne CRM Foundation 9.2 Allows Low‑Privileged Attackers to Take Over the System

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Allows Takeover of Oracle JD Edwards EnterpriseOne CRM Foundation
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Allows Takeover of Oracle JD Edwards EnterpriseOne CRM Foundation
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne CRM Foundation product of Oracle JD Edwards (component: CRM Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne CRM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne CRM Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Crm Foundation
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_crm_foundation:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Crm Foundation
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Crm Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:37.397Z

Reserved: 2026-07-08T15:51:40.540Z

Link: CVE-2026-60489

cve-icon Vulnrichment

Updated: 2026-07-24T18:23:16.395Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function