Executive brief
A vulnerability in Oracle's JD Edwards EnterpriseOne Configurator could allow an authorized user to disrupt business operations or access sensitive data. An attacker could cause the system to crash or hang, resulting in a denial of service, and may also be able to view, modify, or delete certain configuration data. This affects the Configuration Management component used by organizations to manage complex product specifications.
Technical details
A vulnerability exists in the Configuration Management component of Oracle JD Edwards EnterpriseOne Configurator version 9.2. The flaw is reachable via HTTP over a network and requires low-privileged authentication, though it is characterized by high attack complexity. Successful exploitation allows an attacker to cause a complete denial of service (hang or repeatable crash) and provides unauthorized read, update, insert, or delete access to a subset of the application's data. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle JD Edwards EnterpriseOne Configurator 9.2
Timeline
- 2026-07-21: disclosed: Initial advisory publication by Oracle.