Impact
Oracle Time and Labor of Oracle E‑Business Suite is affected by a flaw in the Internal Operations component. A low‑privileged attacker with network access via HTTP can exploit the vulnerability to create, delete or modify critical data. Successful exploitation would grant the attacker unauthorized access to sensitive information and potentially full control of all data exposed through the Time and Labor application.
Affected Systems
Supported affected releases span Oracle Time and Labor versions 12.2.3 through 12.2.15. These versions are impacted by a flaw that can be remedied by applying the Oracle Security Patch released in the July 2026 security alerts. Installations running within this version range should upgrade to the patched release.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high confidentiality and integrity impact. The EPSS score of less than 1% suggests a low overall likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Attackers appear to need only a low‑privileged authenticated session with HTTP access; no elevated rights are required to trigger the malicious behavior.
OpenCVE Enrichment