Executive brief
Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software for managing enterprise resources, contains a critical security vulnerability in its security component. An unauthorized person can remotely take full control of the system over the network without needing a username or password. This could lead to a total loss of data confidentiality and business operations, potentially allowing an attacker to access sensitive corporate information or disrupt essential services.
Technical details
A vulnerability classified as Improper Access Control (CWE-284) exists in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools. The flaw is located within the JDENET networking protocol handling. An unauthenticated attacker can exploit this vulnerability over a network without user interaction to achieve a complete compromise of the JD Edwards EnterpriseOne Tools environment. The vulnerability affects versions 9.2.0.0 through 9.2.26.2. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the system.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published