Description
Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (France) accessible data as well as unauthorized read access to a subset of Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who gains network access over HTTP can exploit a flaw in the French HR Payroll component of Oracle HRMS (France), allowing unauthorized update, insert or delete operations on data normally protected by access controls and the unauthorized reading of a restricted subset of data. The vulnerability results in a loss of confidentiality and integrity of payroll and personnel records, although availability is not affected. The weakness aligns with CWE‑284, which denotes authorization flaws that permit resource access beyond the intended scope.

Affected Systems

Oracle HRMS (France), part of Oracle E‑Business Suite, is affected in all supported releases from version 12.2.3 through 12.2.15 inclusive. Users operating within this version range should confirm their exact sub‑release and refer to Oracle’s July 2026 CPU advisory for patch details.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 indicates a moderate level of risk, with relatively low confidentiality and integrity impacts but no availability consequences. The vulnerability is easily exploitable: a low‑privileged account that can reach the HRMS instance via HTTP can perform the exploit without requiring user interaction. However, the EPSS score of less than 1% suggests that, at this time, the exploitation probability is very low, and the issue is not presently catalogued in CISA’s KEV list. The likely attack vector is remote over HTTP, requiring only network connectivity to the HRMS endpoint and a non‑privileged account.

Generated by OpenCVE AI on August 4, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle HRMS (France) to the latest patched release as specified in the Oracle CPU July 2026 advisory.
  • Restrict HTTP access to the HRMS instance by configuring firewall rules and enforcing strict role‑based access control for low‑privileged users.
  • Enable and monitor audit logging for unauthorized insert, update or delete operations within the HRMS database.

Generated by OpenCVE AI on August 4, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Data Modification and Read in Oracle HRMS (France)

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Data Modification and Read in Oracle HRMS (France)

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Attack Enabling Unauthorized Data Modification and Read in Oracle HRMS (France)

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Attack Enabling Unauthorized Data Modification and Read in Oracle HRMS (France)
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (France) accessible data as well as unauthorized read access to a subset of Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T10:47:11.929Z

Reserved: 2026-07-08T15:51:40.531Z

Link: CVE-2026-60344

cve-icon Vulnrichment

Updated: 2026-07-27T10:41:39.555Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses