Description
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Norway). CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle HRMS (Norway) allows a highly privileged user who can reach the system over HTTP to compromise the application. The weakness is a privilege‑escalation or improper access control issue that can lead to loss of confidentiality, integrity, and availability of payroll data and ultimately to full takeover of the HRMS instance.

Affected Systems

Oracle Corporation’s Oracle HRMS (Norway) component of Oracle E‑Business Suite, specifically the Norway Payroll module, in the supported versions 12.2.8 through 12.2.15 is vulnerable. No other Oracle products or versions are currently listed as affected.

Risk and Exploitability

The CVSS 3.1 base score of 6.6 denotes a moderate severity, while the EPSS score of less than 1 % and the absence from CISA’s KEV catalog indicate limited momentum in the wild. The attack vector requires network‑exposed HTTP access and accounts with high‑privileges, so the risk is concentrated for environments where privileged users or compromised credentials already exist. If such conditions are met, an attacker can gain complete control over the HRMS service.

Generated by OpenCVE AI on August 4, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Oracle’s Security Alert and vendor resources for any update or patch addressing this issue and apply it when available.
  • Limit HTTP access to the HRMS (Norway) instance to trusted IP ranges or VPN‑only connections via firewall or ACL rules.
  • Enforce least privilege and strong authentication for HRMS high‑privileged accounts, and consider disabling or restricting accounts that are not required.
  • Enable detailed audit logging for HRMS user activity and monitor logs for anomalous behavior to detect potential exploitation.

Generated by OpenCVE AI on August 4, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Enables Full Takeover of Oracle HRMS (Norway)

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Enables Full Takeover of Oracle HRMS (Norway)

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Norway). CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:32:18.272Z

Reserved: 2026-07-08T15:51:55.599Z

Link: CVE-2026-60892

cve-icon Vulnrichment

Updated: 2026-07-24T17:32:11.348Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses