Vulnerability in Oracle JD Edwards EnterpriseOne Configurator Affects Data Security
CVE-2026-60620

6.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60620?

A vulnerability in Oracle's JD Edwards EnterpriseOne Configurator allows attackers with low privileges and network access to exploit the system. This can lead to significant disruptions, including unauthorized updates, inserts, or deletions of sensitive data within the application. Attackers can also compromise the system's operations, resulting in repeated crashes or denial of service. The potential for unauthorized read access to critical data heightens the security risks for organizations relying on JD Edwards EnterpriseOne Configurator.

Affected Version(s)

JD Edwards EnterpriseOne Configurator 9.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.