Description
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Configuration Workbench accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker with low privileges who can reach the system over HTTP to compromise the Oracle HCM Configuration Workbench. Successful exploitation leads to unauthorized access to critical data, potentially giving the attacker full read access to all data exposed by the Workbench. The weakness manifests as a confidentiality impact, with a CVSS 3.1 Base Score of 6.5 and a vector indicating that the attack can be performed over the network without user interaction. The vulnerability is classified under CWE-200 (Information Exposure).

Affected Systems

Affected vendors and products include Oracle Corporation’s Oracle HCM Configuration Workbench, a component of Oracle E‑Business Suite. The vulnerability applies to supported versions ranging from 12.2.3 through 12.2.15. Earlier or later releases are not known to be affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that the vulnerability is expected to be rarely exploited, and it is not currently listed in CISA’s KEV catalog. However, because the attack requires only network access via HTTP and low‑privileged credentials, the practical risk remains significant for environments that expose the Workbench over a network. An attacker could leverage the vulnerability to read sensitive data that the Workbench makes available, thereby compromising confidentiality.

Generated by OpenCVE AI on August 2, 2026 at 20:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade Oracle HCM Configuration Workbench to a version that removes the vulnerability.
  • Restrict HTTP access to the Configuration Workbench to the minimum necessary network segments or require VPN connectivity.
  • Review user privileges and enforce the principle of least privilege for all accounts that have access to the Workbench.

Generated by OpenCVE AI on August 2, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Information Exposure in Oracle HCM Configuration Workbench

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Vulnerability in Oracle HCM Configuration Workbench Enables Unauthorized Data Access
Weaknesses CWE-284

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Vulnerability in Oracle HCM Configuration Workbench Enables Unauthorized Data Access
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Configuration Workbench accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hcm Configuration Workbench
CPEs cpe:2.3:a:oracle:hcm_configuration_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hcm Configuration Workbench
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Hcm Configuration Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:24:37.407Z

Reserved: 2026-07-08T15:51:55.600Z

Link: CVE-2026-60899

cve-icon Vulnrichment

Updated: 2026-07-24T17:24:29.561Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor