Network Vulnerability in JD Edwards EnterpriseOne Tools by Oracle
CVE-2026-60346

3.7LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60346?

A vulnerability exists in Oracle's JD Edwards EnterpriseOne Tools, specifically in the Interoperability Security component. This weakness allows an unauthenticated attacker, who has network access via JDENET, to potentially compromise the tools. Exploiting this flaw could enable the attacker to execute unauthorized actions, which may lead to a partial denial of service (DoS) for JD Edwards EnterpriseOne Tools users. This emphasizes the importance of maintaining security measures against unauthorized network access to protect the integrity of the system.

Affected Version(s)

JD Edwards EnterpriseOne Tools 9.2.26.3

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.