Description
Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Human Resources component of Oracle JD Edwards allows a low‑privileged attacker who can reach the system through JDENET to compromise the application. Exploitation can lead to full takeover of the HR module, exposing or altering confidential employee data and disrupting HR services. The weakness results in confidentiality, integrity, and availability loss, as reflected by the CVSS vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H.

Affected Systems

The affected product is Oracle JD Edwards EnterpriseOne Human Resources Management 9.2. Only the 9.2 release is mentioned as vulnerable, and the flaw resides in the Human Resources component. No other versions are currently known to be impacted.

Risk and Exploitability

With a CVSS base score of 7.5 the vulnerability is considered high severity. The EPSS score is less than 1%, indicating that the probability of exploitation in the wild is currently low, and it is not listed in the CISA KEV catalog. However, the attack vector requires network access via JDENET and the attacker only needs low privileges, meaning that an internal threat actor with access to that network could attempt the exploit. Because the flaw is difficult to exploit, organizations should still mitigate promptly.

Generated by OpenCVE AI on August 2, 2026 at 22:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle 2026 CPU patch that resolves CVE‑2026‑60498, as detailed in the Oracle CPU July 2026 advisory.
  • Limit JDENET connectivity to trusted hosts and enforce network segmentation so that only necessary systems can reach the HR application.
  • Enable comprehensive logging for HR module access and review logs regularly for anomalous activity that may indicate attempted exploitation.
  • If the patch cannot be applied immediately, disable the JDENET service or isolate the HR deployment from the rest of the network until remediation is complete.

Generated by OpenCVE AI on August 2, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Takeover of JD Edwards EnterpriseOne Human Resources Management via JDENET
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover of JD Edwards EnterpriseOne Human Resources Management via JDENET
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Human Resources Management
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_human_resources_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Human Resources Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Human Resources Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:57.368Z

Reserved: 2026-07-08T15:51:40.541Z

Link: CVE-2026-60498

cve-icon Vulnrichment

Updated: 2026-07-24T15:43:01.351Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function