Executive brief
A critical vulnerability exists in Oracle JD Edwards EnterpriseOne General Ledger, a core financial management system. An attacker with low-level access to the network can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive financial data, unauthorized modification of accounting records, and disruption of business operations.
Technical details
A vulnerability in the E1 Foundation component of Oracle JD Edwards EnterpriseOne General Ledger (version 9.2) is classified as Improper Privilege Management (CWE-269). The flaw is easily exploitable via the SMB protocol by a low-privileged attacker with network access. Successful exploitation results in a scope change (S:C), meaning the attacker can compromise the underlying host or integrated products beyond the JD Edwards application itself. This leads to a total loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle JD Edwards EnterpriseOne General Ledger 9.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle security alert published