Executive brief
A security vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure components used to manage enterprise resource planning (ERP) software. An attacker who already has low-level access to the underlying server could potentially modify or delete certain business data and cause minor service disruptions. While the impact is limited to specific data and partial service availability, it represents a risk to the integrity of the enterprise environment.
Technical details
This vulnerability affects the Enterprise Infrastructure Security component of JD Edwards EnterpriseOne Tools version 9.2.26.3. It is classified as difficult to exploit (AC:H) and requires the attacker to have local logon credentials to the infrastructure where the software executes (AV:L). Successful exploitation allows a low-privileged user to perform unauthorized updates, insertions, or deletions of accessible data. Additionally, the flaw can be leveraged to cause a partial denial of service (DoS). The vulnerability does not allow for the unauthorized disclosure of information (Confidentiality is not impacted). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.26.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published by Oracle and NVD