Executive brief
A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure services used to manage enterprise resource planning (ERP) software. An unauthenticated attacker can exploit this flaw over the network to gain complete control of the system. This could lead to the total loss of confidentiality, integrity, and availability of business-critical data and operations.
Technical details
A vulnerability in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (specifically versions 9.2.0.0 through 9.2.26.2) is classified as improper access control (CWE-284). The flaw is easily exploitable by an unauthenticated attacker with network access via the JDENET protocol. Successful exploitation allows the attacker to compromise the JD Edwards EnterpriseOne Tools environment completely, resulting in a full takeover of the affected component. The vulnerability has a CVSS 3.1 base score of 9.8, reflecting high impacts on confidentiality, integrity, and availability.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published