Executive brief
A vulnerability exists in Oracle JD Edwards EnterpriseOne General Ledger, a comprehensive financial management software suite. An unauthenticated attacker could exploit this flaw over the network to cause a total system crash or service outage, disrupting business operations. Additionally, the attacker may be able to view, modify, or delete a limited amount of sensitive financial data within the system.
Technical details
A vulnerability in the E1 Foundation component of Oracle JD Edwards EnterpriseOne General Ledger (version 9.2) allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit is characterized as difficult to execute (High Attack Complexity) but can result in a complete denial-of-service (hang or repeatable crash). Furthermore, successful exploitation grants unauthorized read access to a subset of data and the ability to perform unauthorized updates, inserts, or deletions of certain accessible data. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle JD Edwards EnterpriseOne General Ledger 9.2
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date