Description
Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and unauthorized read access to a subset of JD Edwards EnterpriseOne General Ledger accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).
Published: 2026-07-21
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can reach JD Edwards EnterpriseOne General Ledger via HTTP can exploit a difficult‑to‑exploit flaw in version 9.2 that allows the attacker to cause the application to crash repeatedly, leading to a denial of service. In addition to availability damage, the vulnerability permits the attacker to update, insert, or delete accessible data and to read a subset of the data, exposing confidential information. The weakness is improper access control, as the application fails to enforce proper authorization checks and to protect confidential data.

Affected Systems

Oracle Corporation’s JD Edwards EnterpriseOne General Ledger, component E1 Foundation, version 9.2. The product is accessed over HTTP and the vulnerability is present only in the 9.2 release.

Risk and Exploitability

The CVSS 3.1 score of 7.0 indicates a high likelihood of availability impact while confidentiality and integrity are affected at a low level. The EPSS score of less than 1 % suggests that exploit attempts are very rare at present, and the vulnerability is not listed in the CISA KEV catalog, implying it is not commonly exploited in the wild. Nevertheless, because the vector is remote and unauthenticated, an attacker with network access can reach the vulnerable points solely over HTTP, and successful exploitation requires the attacker to trigger specific application logic that permits data manipulation. Given the difficulty of exploiting the flaw, exploitation is unlikely to succeed without in‑depth knowledge of the application internals, but the impact—if achieved—would be significant.

Generated by OpenCVE AI on August 4, 2026 at 03:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle JD Edwards EnterpriseOne patches for version 9.2 as published in the CPU July 2026 advisory.
  • Limit HTTP access to the JD Edwards EnterpriseOne General Ledger to trusted hosts only, blocking all other network traffic.
  • Enforce strict role‑based access controls and review the application for proper authorization checks to prevent unauthorized data manipulation.

Generated by OpenCVE AI on August 4, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Causing Data Manipulation and Denial of Service in JD Edwards 9.2 General Ledger

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Causing Data Manipulation and Denial of Service in JD Edwards 9.2 General Ledger

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service and Unauthorized Data Modification in JD Edwards EnterpriseOne General Ledger 9.2
Weaknesses CWE-200
CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service and Unauthorized Data Modification in JD Edwards EnterpriseOne General Ledger 9.2
Weaknesses CWE-200
CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and unauthorized read access to a subset of JD Edwards EnterpriseOne General Ledger accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone General Ledger
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_general_ledger:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone General Ledger
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone General Ledger
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:42.966Z

Reserved: 2026-07-08T15:51:40.540Z

Link: CVE-2026-60494

cve-icon Vulnrichment

Updated: 2026-07-24T18:15:31.827Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses