Description
Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne HCM Foundation. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle JD Edwards EnterpriseOne HCM Foundation version 9.2 allows a low‑privileged attacker who can reach the system over HTTP to gain full control of the application. The vulnerability exists in the Time Accounting and HRM Base components and, if exploited, permits the attacker to read, modify or delete data and disrupt the availability of the system, affecting confidentiality, integrity and availability.

Affected Systems

The vulnerability targets Oracle JD Edwards EnterpriseOne HCM Foundation 9.2, specifically its Time Accounting and HRM Base modules. All installations of this release that include those modules are susceptible unless already patched.

Risk and Exploitability

The CVSS base score of 7.5 signals a high severity threat; however, the EPSS score of less than 1% indicates the likelihood of immediate exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. Attackers only need low privileges and network connectivity over HTTP, so the attack can be launched from a host that has network access to the JD Edwards servers. It is inferred that the attacker’s access could be internal or from an exposed network, as the description does not specify the exact attack surface, but it requires an HTTP connection to the vulnerable system.

Generated by OpenCVE AI on August 2, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch released in the July 2026 CPU alert for JD Edwards EnterpriseOne HCM Foundation 9.2.
  • Restrict HTTP access to JD Edwards servers by configuring firewalls or intrusion prevention to allow only trusted internal hosts.
  • Enforce least‑privilege policies on all service accounts that interact with the application and monitor for anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Full Control of JD Edwards EnterpriseOne HCM Foundation

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Takeover via HTTP in JD Edwards EnterpriseOne HCM Foundation 9.2
Weaknesses CWE-264

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Takeover via HTTP in JD Edwards EnterpriseOne HCM Foundation 9.2
Weaknesses CWE-264
CWE-269

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne HCM Foundation product of Oracle JD Edwards (component: Time Accounting and HRM Base). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne HCM Foundation. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne HCM Foundation. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Hcm Foundation
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_hcm_foundation:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Hcm Foundation
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Hcm Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:32:24.359Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60619

cve-icon Vulnrichment

Updated: 2026-07-27T12:32:18.913Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function