Vulnerability in JD Edwards EnterpriseOne Advanced Pricing - Procurement by Oracle
CVE-2026-60496

7.5HIGH

What is CVE-2026-60496?

A vulnerability exists within the JD Edwards EnterpriseOne Advanced Pricing - Procurement product, allowing low-privileged attackers with network access through JDENET to potentially compromise the system. Affected users may face significant risks including unauthorized access to sensitive functions, which can lead to a complete takeover of the JD Edwards EnterpriseOne Advanced Pricing functionalities. The supported version at risk includes 9.2, underscoring the importance of immediate remediation.

Affected Version(s)

JD Edwards EnterpriseOne Advanced Pricing - Procurement 9.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.