Junglewise Threat Intelligence

CVE-2026-60346: Oracle JD Edwards EnterpriseOne Tools partial DoS in Interoperability Security

CVE-2026-60346 · Severity: low · CVSS 3.7 · Published 2026-07-21

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker could remotely cause a partial denial of service, potentially slowing down or disrupting specific business operations. While the impact is limited to system availability, it could interfere with the reliability of interoperability services within the organization.

Technical details

A vulnerability in the Interoperability Security component of Oracle JD Edwards EnterpriseOne Tools (specifically version 9.2.26.3) allows for a partial denial of service (DoS). The flaw is exploitable by an unauthenticated attacker with network access via the JDENET protocol. Exploitation is considered difficult (High Attack Complexity), likely requiring specific timing or environmental conditions to successfully impact system availability. The vulnerability does not affect confidentiality or integrity, only availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.26.3

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD entry published

References

Related threats