Vulnerability in the JD Edwards EnterpriseOne Requirements Planning product of Oracle JD Edwards (component: Requirements Planning). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Requirements Planning. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Requirements Planning. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
References
| Link | Resource |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
06 Aug 2026, 14:53
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.oracle.com/security-alerts/cpujul2026.html - Vendor Advisory | |
| CPE | cpe:2.3:a:oracle:jd_edwards_enterpriseone_requirements_planning:9.2:*:*:*:*:*:*:* | |
| First Time |
Oracle
Oracle jd Edwards Enterpriseone Requirements Planning |
24 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-306 |
21 Jul 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-21 22:17
Updated : 2026-08-06 14:53
NVD link : CVE-2026-60495
Mitre link : CVE-2026-60495
CVE.ORG link : CVE-2026-60495
JSON object : View
Products Affected
oracle
- jd_edwards_enterpriseone_requirements_planning
CWE
CWE-306
Missing Authentication for Critical Function
