Description
Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Solution Advisor. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Solution Advisor. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle JD Edwards EnterpriseOne Solution Advisor 9.2 that enables an attacker with low user privileges who can reach the application over HTTP to compromise the solution. The flaw allows the attacker to take control of the application, affecting confidentiality, integrity, and availability of the component. The vulnerability is documented as an easily exploitable issue that can result in a full takeover of the Solution Advisor.

Affected Systems

Oracle Corporation’s JD Edwards EnterpriseOne Solution Advisor, version 9.2, is affected. No other versions are listed as vulnerable in the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of immediate exploitation in the wild, and the issue is not included in the CISA KEV catalog. The attack vector is remote over HTTP; the attacker requires only low privileges and network access does not need local or elevated privileges to exploit the vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 17:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for JD Edwards EnterpriseOne Solution Advisor 9.2
  • Restrict HTTP access to the Solution Advisor to trusted internal networks and enable HTTPS to protect traffic
  • Enforce network segmentation to isolate the Solution Advisor servers from unauthorized external traffic

Generated by OpenCVE AI on August 4, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title HTTP-Based Low-Privilege Exploit Compromises JD Edwards EnterpriseOne Solution Advisor

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in JD Edwards EnterpriseOne Solution Advisor 9.2
Weaknesses CWE-269
CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via HTTP in JD Edwards EnterpriseOne Solution Advisor 9.2
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Solution Advisor product of Oracle JD Edwards (component: Solution Advisor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Solution Advisor. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Solution Advisor. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Solution Advisor
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_solution_advisor:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Solution Advisor
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Solution Advisor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:56:00.707Z

Reserved: 2026-07-08T15:51:40.541Z

Link: CVE-2026-60499

cve-icon Vulnrichment

Updated: 2026-07-24T15:42:24.522Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:51.023

Modified: 2026-08-06T14:54:33.730

Link: CVE-2026-60499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function