2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46908 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46908

Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable. While the vulnerability is in JD Edwards EnterpriseOne Accounts Payable, attacks may significantly impact additional products (scope change). Successful att CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46907 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46907

Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Oracle JD Edwards (component: Order Promising Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Order Promising. While the vulnerability is in JD Edwards EnterpriseOne Order Promising, attacks may significantly impact additional products (scope change). Succes CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46906 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46906

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks CVSSv3.1 9.6 (CRITICAL)

CWECWE 284VNDVulnerabilityTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46905 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46905

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availabi CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46904 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46904

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integr CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 284VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 10:54Z
HIGH

CVE-2026-46903 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46903

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integ CVSSv3.1 8.8 (HIGH)

CWECWE 269CWECWE 306CWECWE 287VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46902 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46902

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 284VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46901 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46901

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful CVSSv3.1 9.9 (CRITICAL)

CWECWE 269CWECWE 284VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46900 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46900

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successfu CVSSv3.1 9.9 (CRITICAL)

CWECWE 269CWECWE 284VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46899 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46899

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful CVSSv3.1 9.6 (CRITICAL)

CWECWE 269CWECWE 284VNDVulnerabilityTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-17
2026-06-17 10:54Z
HIGH

CVE-2026-46898 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46898

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46897 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46897

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46896 — Vulnerability: Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46896

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successfu CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46895 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46895

Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful CVSSv3.1 9.9 (CRITICAL)

CWECWE 269CWECWE 284VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:54Z
HIGH

CVE-2026-46894 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46894

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle iSupplier Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle iSupplier Portal. CVSS 3.1 CVSSv3.1 8.0 (HIGH)

CWECWE 352CWECWE 640CWECWE 601VNDVulnerabilityTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46893 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46893

Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne General Ledger. While the vulnerability is in JD Edwards EnterpriseOne General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of th CVSSv3.1 9.9 (CRITICAL)

CWECWE 269VNDVulnerabilityTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46892 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46892

Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD CVSSv3.1 9.1 (CRITICAL)

CWECWE 306CWECWE 284VNDVulnerabilityTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-17
2026-06-17 10:54Z
HIGH

CVE-2026-46891 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46891

Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseO CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDVulnerabilityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46890 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46890

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/ CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 287CWECWE 284VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46889 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46889

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/ CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46887 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46887

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/ CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 10:54Z
HIGH

CVE-2026-46886 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46886

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/A CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 10:54Z
HIGH

CVE-2026-46885 — Vulnerability: Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46885

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/ CVSSv3.1 8.8 (HIGH)

VNDVulnerabilityTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46884 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46884

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/ CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-17
2026-06-17 10:54Z
CRIT

CVE-2026-46883 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46883

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integr CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score