Executive brief
Oracle JD Edwards EnterpriseOne Human Resources Management, a software suite used by organizations to manage employee data and HR processes, contains a high-severity vulnerability. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the HR management system. This could lead to the unauthorized disclosure of sensitive employee information, disruption of HR operations, and loss of data integrity.
Technical details
A vulnerability in the Human Resources component of Oracle JD Edwards EnterpriseOne Human Resources Management version 9.2 allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the affected component. While the specific CWE is not identified in the advisory, the CVSS vector indicates no user interaction is required and the attack complexity is low. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle JD Edwards EnterpriseOne Human Resources Management 9.2
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD.