Vulnerability in JD Edwards EnterpriseOne CRM Foundation by Oracle
CVE-2026-60497
7.5HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-60497?
A security vulnerability has been identified in the JD Edwards EnterpriseOne CRM Foundation product, specifically affecting version 9.2. This vulnerability can be exploited by a low-privileged attacker with network access via JDENET, allowing them to potentially compromise the JD Edwards EnterpriseOne CRM Foundation system. If successfully exploited, this could lead to a complete takeover of the CRM Foundation, impacting the system's confidentiality, integrity, and availability.
Affected Version(s)
JD Edwards EnterpriseOne CRM Foundation 9.2