Executive brief
Oracle JD Edwards EnterpriseOne Human Resources Management, a suite used by organizations to manage employee data and HR processes, contains a vulnerability that could allow an unauthorized takeover of the system. A low-privileged user with network access could exploit this flaw to gain full control over the HR management component. This could lead to the exposure of sensitive employee information, unauthorized changes to HR records, and disruption of business operations.
Technical details
A vulnerability exists in the Human Resources component of Oracle JD Edwards EnterpriseOne Human Resources Management, specifically affecting version 9.2. The flaw is accessible via the JDENET protocol over a network. While the attack complexity is rated as high, a successful exploit by a low-privileged attacker can result in a complete compromise of the component, impacting confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026. Security engineers should apply the relevant patches from Oracle to mitigate the risk of system takeover.
Affected products
- Oracle JD Edwards EnterpriseOne Human Resources Management 9.2
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability as part of the July 2026 CPU.
- 2026-07-21: disclosed: CVE-2026-60498 was published to the NVD.