Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle Time and Labor’s Internal Operations component allows an attacker with low privileges to perform unauthorized creation, deletion or modification of data. Successful exploitation results in loss of data integrity and can trigger a partial denial of service, impacting business operations. Based on the description, it is inferred that the weakness is improper access control, enabling the attacker to bypass the intended authorization checks.

Affected Systems

Oracle Time and Labor, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The issue affects the Internal Operations module and can be reached via the standard HTTP interface.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 reflects moderate to high impact on integrity and availability. The EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers only need low‑privilege access and network connectivity to HTTP to exploit the flaw, making it a network‑based vulnerability that can be leveraged from remote hosts.

Generated by OpenCVE AI on August 4, 2026 at 02:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Implement the Oracle CPU July 2026 patch that addresses the Time and Labor vulnerability.
  • Restrict HTTP access to the Oracle Time and Labor instance to trusted network segments or a VPN, limiting exposure to potential attackers.
  • Review and tighten user privilege assignments to enforce least‑privilege access, reducing the risk that low‑privileged accounts can perform sensitive operations.

Generated by OpenCVE AI on August 4, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation in Oracle Time and Labor via Improper Access Control

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Oracle Time and Labor Improper Access Control Leading to Data Manipulation and Partial Denial of Service

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Oracle Time and Labor Improper Access Control Leading to Data Manipulation and Partial Denial of Service

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:53:14.719Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61012

cve-icon Vulnrichment

Updated: 2026-07-24T14:53:08.269Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses