Description
Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (France) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle HRMS (France) enables a low‑privileged user who can reach the application over HTTP to create, delete, or modify critical data and to obtain unauthorized access to all HRMS data. The issue is an improper access control weakness that impacts both confidentiality and integrity.

Affected Systems

Oracle Corporation’s Oracle HRMS (France) component of the Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. These versions remain supported by Oracle as noted in the vendor advisory.

Risk and Exploitability

The vulnerability is easily exploitable, requiring only an HTTP connection and a low‑privileged account. With a CVSS 3.1 base score of 8.1, the risk to data is significant. The EPSS score of less than 1% indicates that the flaw is not yet commonly seen in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is a network‑accessible HTTP endpoint, making the flaw attractive to threat actors who can reach the HRMS interface.

Generated by OpenCVE AI on August 2, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle E‑Business Suite patch that addresses the access control flaw in Oracle HRMS (France).
  • Restrict network traffic to the HRMS HTTP endpoints to only trusted internal hosts or VPNs, blocking all other inbound requests.
  • Enforce tight role‑based access controls for HRMS users and review permissions so that only authorized personnel can perform data‑modifying operations.

Generated by OpenCVE AI on August 2, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Vulnerability in Oracle HRMS (France) Enables Unauthorized Data Modification and Access

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Vulnerability in Oracle HRMS (France) Enables Unauthorized Data Modification and Access

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (France) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (France) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Hrms Human Resources Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:25:57.225Z

Reserved: 2026-07-08T15:51:55.604Z

Link: CVE-2026-60965

cve-icon Vulnrichment

Updated: 2026-07-24T15:25:49.555Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:30.567

Modified: 2026-07-24T18:34:18.750

Link: CVE-2026-60965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses