Description
Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in the Human Resources component of JD Edwards EnterpriseOne allows a low privileged attacker with network access via HTTP to exploit a weakness. An authenticated user with low privileges can perform the exploit and gain complete control of the system, compromising confidentiality, integrity, and availability. The vulnerability is a classic missing access‑control issue.

Affected Systems

Oracle Corporation JD Edwards EnterpriseOne Human Resources Management version 9.2 is affected. This product processes HR data and is typically exposed to corporate intranets or the public internet via HTTP.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is via HTTP requests to the HR web interface from any host with network access. The CVSS score of 8.8 reflects a high severity impact. The EPSS score is below 1 %, indicating a low probability of current exploitation, and the vulnerability has not been listed in the CISA KEV catalog. However, because the attack vector is network‑based and requires only low privileges, an attacker can reach the target from anywhere in the network. Exploitation would involve sending specially crafted HTTP requests to the HR web interface, resulting in code execution and full administrative takeover.

Generated by OpenCVE AI on August 5, 2026 at 02:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the available Oracle patch for JD Edwards EnterpriseOne HR 9.2 released in the July 2026 CPU.
  • Restrict direct HTTP access to the HR application by firewalls, VPNs, or internal network segmentation so only trusted hosts can reach the service.
  • Ensure that the application uses strong authentication and limits roles to the minimum required, following the principle of least privilege, and disable any default privileged accounts.
  • Monitor authentication logs for repeated failed logins and anomalous HTTP traffic near the HR endpoint.

Generated by OpenCVE AI on August 5, 2026 at 02:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title JD Edwards EnterpriseOne HR 9.2 Access Control Vulnerability Enables System Takeover

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title JD Edwards EnterpriseOne HR 9.2 Access Control Vulnerability Enables System Takeover

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full System Takeover in JD Edwards EnterpriseOne HR Management
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full System Takeover in JD Edwards EnterpriseOne HR Management
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Human Resources Management
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_human_resources_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Human Resources Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Human Resources Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:55.746Z

Reserved: 2026-07-08T15:51:40.540Z

Link: CVE-2026-60493

cve-icon Vulnrichment

Updated: 2026-07-24T18:18:38.954Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function