Description
Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne HCM Foundation and unauthorized read access to a subset of JD Edwards EnterpriseOne HCM Foundation accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the JD Edwards EnterpriseOne HCM Foundation 9.2 OW HR PR Foundation component lets an attacker who can reach the application’s HTTP interface send a crafted request that causes the service to hang or crash, resulting in a complete denial of service. The same request also permits reading a subset of data that should be protected, giving the attacker unauthorized access to sensitive information. The CVSS 3.1 vector, AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H, indicates that the vulnerability can be triggered by a low‑privileged network user without user interaction, producing low confidentiality loss but high availability loss.

Affected Systems

The vulnerability affects Oracle JD Edwards EnterpriseOne HCM Foundation version 9.2. No other Oracle products or versions are listed as impacted by the CNA.

Risk and Exploitability

Because the attack can be launched over an open HTTP port and the required privilege level is low, the EPSS score of less than 1% indicates a low but nonzero chance of exploitation. The CVSS Base 7.1 reflects moderate to high impact on confidentiality and high impact on availability. The vulnerability is not yet in CISA’s KEV catalog. In practice an attacker would send a specialized HTTP request to the OW HR PR Foundation endpoint, which triggers both the denial of service and the data leak; the lack of a user‑interaction requirement means the attack can be carried out automatically from any networked machine that can reach the target.

Generated by OpenCVE AI on August 4, 2026 at 03:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s July 2026 CPU patch for JD Edwards EnterpriseOne HCM Foundation 9.2
  • Restrict HTTP access to the JD Edwards server so that only trusted, privileged accounts can reach the OW HR PR Foundation endpoint
  • Monitor application logs for signs of hangs, crashes, or abnormal data reads and configure alerts for such events

Generated by OpenCVE AI on August 4, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Attack Enables Denial of Service and Data Exposure in JD Edwards EnterpriseOne HCM Foundation 9.2

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Attack Enables Denial of Service and Data Exposure in JD Edwards EnterpriseOne HCM Foundation 9.2

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Web-based Denial of Service and Unauthorized Data Access in JD Edwards EnterpriseOne HCM Foundation 9.2
Weaknesses CWE-284
CWE-749

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Web-based Denial of Service and Unauthorized Data Access in JD Edwards EnterpriseOne HCM Foundation 9.2
Weaknesses CWE-284
CWE-749

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: OW HR PR Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne HCM Foundation and unauthorized read access to a subset of JD Edwards EnterpriseOne HCM Foundation accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Hcm Foundation
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_hcm_foundation:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Hcm Foundation
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Hcm Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:19:49.076Z

Reserved: 2026-07-08T15:51:40.540Z

Link: CVE-2026-60492

cve-icon Vulnrichment

Updated: 2026-07-24T18:19:40.555Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management