Description
Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle US Federal Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle US Federal Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle US Federal Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle US Federal Human Resources component of Oracle E-Business Suite is vulnerable to a low-privileged, network-based attack that allows an attacker to create, delete, or modify critical data. The impact is significant, as the attacker can compromise confidentiality and integrity of all data accessible through the application, potentially gaining complete access to the database. The weakness appears to be an access control flaw that permits privileged actions without proper authorization checks.

Affected Systems

Vendors affected: Oracle Corporation. Products impacted are Oracle US Federal Human Resources, version range 12.2.3 to 12.2.15 in the Internal Operations component. No other vendors or topographical product names are listed.

Risk and Exploitability

The base CVSS 3.1 score of 8.1 indicates a high severity issue with high confidentiality and integrity impact. The EPSS score of less than 1% suggests low current exploitation likelihood, but the vulnerability is easily exploitable for network users with HTTP access. The product is not listed in the CISA KEV catalog, so there is no evidence of widespread exploitation yet. The likely attack vector is a standard HTTP request to a privileged endpoint; the vulnerability can be leveraged by an attacker who is not authenticated or holds a low privileged account within the network. The overall risk is moderate to high for organizations that expose the application to external or untrusted traffic, and it warrants timely remediation.

Generated by OpenCVE AI on August 5, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle US Federal Human Resources as detailed in the CPU July 2026 advisory
  • Restrict HTTP access to the application via firewall rules or VPN, limiting exposure to trusted networks only
  • Enforce strict role-based access controls in the application to ensure users can only perform actions that correspond to their assigned permissions

Generated by OpenCVE AI on August 5, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Oracle US Federal Human Resources Access Control Flaw Allows Unauthorized Data Modification
Weaknesses CWE-284
CWE-862

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification via HTTP in Oracle US Federal Human Resources
Weaknesses CWE-284
CWE-285

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Data Modification via HTTP in Oracle US Federal Human Resources
Weaknesses CWE-284
CWE-285

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification Vulnerability in Oracle US Federal Human Resources via HTTP
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification Vulnerability in Oracle US Federal Human Resources via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle US Federal Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle US Federal Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle US Federal Human Resources accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle us Federal Human Resources
CPEs cpe:2.3:a:oracle:us_federal_human_resources:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle us Federal Human Resources
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle E-business Suite Us Federal Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:12:59.172Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:31.330

Modified: 2026-08-06T15:01:35.937

Link: CVE-2026-60982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses