Executive brief
A security vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An attacker with physical access to the local network could potentially view or modify a limited amount of sensitive business data. Exploiting this issue is difficult as it requires a legitimate user to perform a specific action while the attacker is active on the network.
Technical details
A vulnerability in the Installation Security component of Oracle JD Edwards EnterpriseOne Tools (version 9.2.26.3) allows an unauthenticated attacker with access to the physical communication segment (adjacent network) to compromise the application. The vulnerability is classified as difficult to exploit (Attack Complexity: High) and requires human interaction from a person other than the attacker (User Interaction: Required). Successful exploitation can result in unauthorized read access to a subset of data, as well as unauthorized update, insert, or delete access to some accessible data. The vulnerability has been assigned a CVSS 3.1 base score of 3.7, reflecting low impacts to confidentiality and integrity with no impact on availability.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.26.3
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date