Description
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in takeover of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle HCM Configuration Workbench vulnerability allows an attacker with high‑privileged credentials and network access to the HTTP interface to take full control of the workbench. Successful exploitation can compromise confidentiality, integrity, and availability for all processes that rely on the configuration workbench, effectively enabling a takeover of the entire Oracle E‑Business Suite Rapid Implementation component.

Affected Systems

Oracle HCM Configuration Workbench, part of Oracle E‑Business Suite's Rapid Implementation component, is affected for versions 12.2.3 through 12.2.15. Users of these versions are exposed to an HTTP service that can be reached from the network.

Risk and Exploitability

The CVSS 3.1 base score of 7.2 places the vulnerability in the high severity range. However, the EPSS score of less than 1% suggests a very low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. The attack requires high‑privileged credentials and network access to the HTTP endpoint; once those prerequisites are met, the attacker can achieve a full takeover of the configuration workbench.

Generated by OpenCVE AI on August 4, 2026 at 02:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle HCM Configuration Workbench patches or upgrade to a version outside the affected range (12.2.3–12.2-15).
  • Restrict the HTTP interface of the configuration workbench to trusted internal networks or approved IP ranges, limiting exposure to privileged users.
  • Enforce multi‑factor authentication for privileged accounts and monitor system logs for anomalous privileged activity to detect potential compromise.

Generated by OpenCVE AI on August 4, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege HTTP Remote Takeover in Oracle HCM Configuration Workbench
Weaknesses CWE-269
CWE-284
CWE-287

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit Enabling Full Takeover of Oracle HCM Configuration Workbench
Weaknesses CWE-285

Sun, 26 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit Enabling Full Takeover of Oracle HCM Configuration Workbench
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Rapid Implementation). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in takeover of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hcm Configuration Workbench
CPEs cpe:2.3:a:oracle:hcm_configuration_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hcm Configuration Workbench
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hcm Configuration Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:28:59.537Z

Reserved: 2026-07-08T15:51:55.600Z

Link: CVE-2026-60900

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses