CVE-2026-60628
Sicherheitsanfälligkeit im Produkt JD Edwards EnterpriseOne Tools von Oracle JD Edwards (Komponente: Installations-Sicherheit) (CVE-2026-60628)
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- New CVE Received2026-07-21 22:18 UTC· secalert_us@oracle.com
- Affected: JD Edwards EnterpriseOne Tools
- Description: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
- CVSS V3.1: AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
- Reference: https://www.oracle.com/security-alerts/cpujul2026.html
Beschreibung
Sicherheitsanfälligkeit im Produkt JD Edwards EnterpriseOne Tools von Oracle JD Edwards (Komponente: Installations-Sicherheit). Die betroffene unterstützte Version ist 9.2.26.3. Eine schwer auszunutzende Sicherheitslücke ermöglicht es einem nicht authentifizierten Angreifer mit Zugang zum physischen Kommunikationssegment, das an der Hardware angebunden ist, auf der JD Edwards EnterpriseOne Tools ausgeführt wird, die Kompromittierung von JD Edwards EnterpriseOne Tools. Erfolgreiche Angriffe erfordern menschliche Interaktion durch eine Person außer dem Angreifer. Erfolgreiche Ausnutzungen dieser Sicherheitsanfälligkeit können zu unberechtigtem Update-, Einfüge- oder Löschzugriff auf einige von JD Edwards EnterpriseOne Tools zugängliche Daten sowie unberechtigtem Lesenzugriff auf einen Teil der von JD Edwards EnterpriseOne Tools zugänglichen Daten führen. CVSS 3.1 Basiswert 3,7 (Auswirkungen auf Vertraulichkeit und Integrität). CVSS-Vektor: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
Quelle: NVD