CRITICAL🇵🇱 Wersja polska

CVE-2026-60627

CVSS 9.9v3.1pub. 2026-07-21upd. 2026-08-05

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Oracle Jd Edwards Enterpriseone Tools

    APP
    Oracle
    9.2.26.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓same product

Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)

CVE-2026-61272CRITICAL9.8same product

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC)....

CVE-2026-46878CRITICAL9.8PL ✓same product

Krytyczne pominięcie uwierzytelnienia w Oracle JD Edwards EnterpriseOne Tools

CVE-2026-46879CRITICAL9.8PL ✓same product

Obejście uwierzytelnienia w Oracle JD Edwards EnterpriseOne Tools

CVE-2026-46880CRITICAL9.8PL ✓same product

Krytyczna podatność w Oracle JD Edwards EnterpriseOne Tools — przejęcie kontroli