Description
Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Procurement and Subcontract Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Procurement and Subcontract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JD Edwards EnterpriseOne Procurement and Subcontract Management version 9.2 contains an access control flaw that allows a low-privileged user with network connectivity over HTTP to gain full control of the application. The vulnerability is based on missing authentication weaknesses, as indicated by the associated CWE. Attackers can compromise confidentiality, integrity, and availability by exploiting this flaw, resulting in complete takeover of the procurement system.

Affected Systems

Oracle Corporation’s JD Edwards EnterpriseOne Procurement and Subcontract Management product, specifically version 9.2, is the affected suite. The issue resides within the Procurement component and impacts the entire application’s operational integrity.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity rating, while the EPSS score of less than 1% suggests a very low likelihood of widespread exploit activity at the present time. The flaw is not listed in the CISA KEV catalog. An attacker would require only low-level privileges and access to the HTTP interface, making the condition for exploitation minimal but potentially devastating should it be successful.

Generated by OpenCVE AI on August 5, 2026 at 02:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Oracle to obtain and apply an official patch or an updated version that eliminates the flaw
  • Restrict access to the JD Edwards Procurement HTTP endpoints by enforcing network segmentation or firewall rules to block untrusted traffic
  • Enhance authentication and authorization controls on the JD Edwards Procurement interfaces to ensure only properly credentialed accounts can perform privileged operations

Generated by OpenCVE AI on August 5, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Control Flaw Leading to Full Takeover in JD Edwards 9.2

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Takeover in Oracle JD Edwards EnterpriseOne Procurement
Weaknesses CWE-284

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Takeover in Oracle JD Edwards EnterpriseOne Procurement
Weaknesses CWE-284

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of JD Edwards EnterpriseOne Procurement via HTTP
Weaknesses CWE-284

Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Takeover of JD Edwards EnterpriseOne Procurement via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Procurement and Subcontract Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Procurement and Subcontract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Procurement And Subcontract Management
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_procurement_and_subcontract_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Procurement And Subcontract Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Procurement And Subcontract Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T18:20:27.697Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60618

cve-icon Vulnrichment

Updated: 2026-07-29T18:20:24.581Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:02.253

Modified: 2026-08-05T13:07:08.110

Link: CVE-2026-60618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:30:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function