CRITICAL🇵🇱 Wersja polska

CVE-2026-46878

CVSS 9.8v3.1pub. 2026-06-17upd. 2026-06-18

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Oracle Jd Edwards Enterpriseone Tools

    APP
    Oracle
    9.2.0.0 – 9.2.26.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDoS
CWE
References

Related vulnerabilities

CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓same product

Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)

CVE-2026-61272CRITICAL9.8same product

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC)....

CVE-2026-60627CRITICAL9.9PL ✓same product

Krytyczna podatność w Oracle JD Edwards EnterpriseOne Tools — przejęcie systemu

CVE-2026-46879CRITICAL9.8PL ✓same product

Obejście uwierzytelnienia w Oracle JD Edwards EnterpriseOne Tools

CVE-2026-46880CRITICAL9.8PL ✓same product

Krytyczna podatność w Oracle JD Edwards EnterpriseOne Tools — przejęcie kontroli