CVE-2026-60494: Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and unauthorized read acce
Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and unauthorized read access to a subset of JD Edwards EnterpriseOne General Ledger accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).
AI Analysis
Technical Summary
This vulnerability affects Oracle JD Edwards EnterpriseOne General Ledger version 9.2 (component: E1 Foundation). It allows an unauthenticated attacker with network access via HTTP to cause a hang or repeated crash (denial of service) and gain unauthorized ability to update, insert, delete, or read some accessible data. The CVSS 3.1 vector is AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H, reflecting network attack vector, high attack complexity, no privileges or user interaction required, and impacts on confidentiality, integrity, and availability. The Oracle July 2026 Critical Patch Update advisory lists JD Edwards EnterpriseOne 9.2 among affected products with available patches, indicating that remediation is provided through this update. No public exploits are known at this time.
Potential Impact
Successful exploitation can result in denial of service by causing the JD Edwards EnterpriseOne General Ledger to hang or crash repeatedly. Additionally, attackers can gain unauthorized read access to some data and unauthorized update, insert, or delete capabilities on accessible data within the General Ledger component. The impact affects confidentiality, integrity, and availability, but confidentiality and integrity impacts are limited (low), while availability impact is high.
Mitigation Recommendations
Oracle has included JD Edwards EnterpriseOne General Ledger version 9.2 in its July 2026 Critical Patch Update, which provides security patches addressing this vulnerability. Customers should apply the patches from this update promptly to remediate the issue. Oracle strongly recommends remaining on actively supported versions and applying security patches without delay. Patch status is confirmed by the vendor advisory indicating patch availability in the July 2026 CPU. No additional mitigation steps are specified by Oracle.
CVE-2026-60494: Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and unauthorized read acce
Description
Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne General Ledger. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne General Ledger as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne General Ledger accessible data and unauthorized read access to a subset of JD Edwards EnterpriseOne General Ledger accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).
CVSS v3.1
Score 7.0high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Oracle JD Edwards EnterpriseOne General Ledger version 9.2 (component: E1 Foundation). It allows an unauthenticated attacker with network access via HTTP to cause a hang or repeated crash (denial of service) and gain unauthorized ability to update, insert, delete, or read some accessible data. The CVSS 3.1 vector is AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H, reflecting network attack vector, high attack complexity, no privileges or user interaction required, and impacts on confidentiality, integrity, and availability. The Oracle July 2026 Critical Patch Update advisory lists JD Edwards EnterpriseOne 9.2 among affected products with available patches, indicating that remediation is provided through this update. No public exploits are known at this time.
Potential Impact
Successful exploitation can result in denial of service by causing the JD Edwards EnterpriseOne General Ledger to hang or crash repeatedly. Additionally, attackers can gain unauthorized read access to some data and unauthorized update, insert, or delete capabilities on accessible data within the General Ledger component. The impact affects confidentiality, integrity, and availability, but confidentiality and integrity impacts are limited (low), while availability impact is high.
Mitigation Recommendations
Oracle has included JD Edwards EnterpriseOne General Ledger version 9.2 in its July 2026 Critical Patch Update, which provides security patches addressing this vulnerability. Customers should apply the patches from this update promptly to remediate the issue. Oracle strongly recommends remaining on actively supported versions and applying security patches without delay. Patch status is confirmed by the vendor advisory indicating patch availability in the July 2026 CPU. No additional mitigation steps are specified by Oracle.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-07-08T15:51:40.540Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","vendor":"Oracle"}]
Threat ID: 6a5fedee9c2644c7f8d59b12
Added to database: 07/21/2026, 22:08:46 UTC
Last enriched: 07/29/2026, 21:11:19 UTC
Last updated: 09/02/2026, 22:52:13 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.