Description
Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirements Planning). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Requirements Planning. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Requirements Planning. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue is a missing authentication flaw that allows an attacker with low‑privilege network access to the JDENET interface to assume control of the JD Edwards EnterpriseOne Requirements Planning application. The vulnerability requires a network connection, a low privilege account, no user interaction, and high attack complexity. Successful exploitation provides full control of the application, leading to loss of confidentiality, integrity and availability of the underlying business data and services. The weakness is a CWE‑306, missing authentication for a critical operation.

Affected Systems

Oracle JD Edwards EnterpriseOne Requirements Planning version 9.2 is affected. Users running JDENET in a networked environment must be aware that any low‑privileged user with access to JDENET can potentially compromise the application.

Risk and Exploitability

The CVSS base score of 7.5 places the vulnerability in the high‑severity range, and the EPSS score of less than 1 % indicates that routine exploitation traffic is currently low. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network reachability to the JDENET interface and a low‑privileged account, making the attack feasible in a networked setting. Although detection of exploitation may be low, the potential for full application takeover warrants prompt attention.

Generated by OpenCVE AI on August 4, 2026 at 03:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch from the CPU July 2026 security bulletin for JD Edwards EnterpriseOne Requirements Planning 9.2.
  • Limit JDENET access to trusted zones and enforce strong authentication for any low‑privileged users.
  • If a patch cannot immediately be applied, isolate the JD Edwards server from public networks or block JDENET traffic from untrusted hosts.

Generated by OpenCVE AI on August 4, 2026 at 03:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Compromise Vulnerability in JD Edwards EnterpriseOne Requirements Planning

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Compromise Vulnerability in JD Edwards EnterpriseOne Requirements Planning

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title JD Edwards Requirement Planning Vulnerability Enabling Remote Takeover by Low‑Privilege Users
Weaknesses CWE-269

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title JD Edwards Requirement Planning Vulnerability Enabling Remote Takeover by Low‑Privilege Users
Weaknesses CWE-269

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirements Planning). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Requirements Planning. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Requirements Planning. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Requirements Planning
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_requirements_planning:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Requirements Planning
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Requirements Planning
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:58.952Z

Reserved: 2026-07-08T15:51:40.540Z

Link: CVE-2026-60495

cve-icon Vulnrichment

Updated: 2026-07-24T18:00:56.126Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function