Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Sat, 01 Aug 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | JD Edwards EnterpriseOne HR 9.2 Access Control Vulnerability Enables System Takeover |
Mon, 27 Jul 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege HTTP Exploit Enables Full System Takeover in JD Edwards EnterpriseOne HR Management | |
| Weaknesses | CWE-284 |
Fri, 24 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
ssvc
|
Fri, 24 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege HTTP Exploit Enables Full System Takeover in JD Edwards EnterpriseOne HR Management | |
| Weaknesses | CWE-284 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Human Resources Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle jd Edwards Enterpriseone Human Resources Management |
|
| CPEs | cpe:2.3:a:oracle:jd_edwards_enterpriseone_human_resources_management:9.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle jd Edwards Enterpriseone Human Resources Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:35:31.687Z
Updated: 2026-07-25T03:55:55.746Z
Reserved: 2026-07-08T15:51:40.540Z
Link: CVE-2026-60493
Updated: 2026-07-24T18:18:38.954Z
No data.
No data.