Executive brief
A vulnerability exists in Oracle's JD Edwards EnterpriseOne HCM Foundation, a suite used for human capital management and payroll operations. An attacker with basic user credentials can exploit this flaw over the network to crash the system or access sensitive organizational data. This could lead to significant operational downtime and unauthorized exposure of employee or HR records.
Technical details
A vulnerability in the OW HR PR Foundation component of Oracle JD Edwards EnterpriseOne HCM Foundation version 9.2 allows for unauthorized data access and denial-of-service. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can result in a frequently repeatable crash or system hang (complete DOS) and unauthorized read access to a subset of the application's data. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle JD Edwards EnterpriseOne HCM Foundation业务 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory