Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. While the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data as well as unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Internal Operations component of Oracle Time and Labor that allows an attacker with high privileges and network access over HTTP to compromise the system. Exploitation can lead to unauthorized access to critical data, full access to all Oracle Time and Labor accessible data, and the ability to insert, update or delete information. The weakness is classified as a high privileged attack with potential for integrity impacts.

Affected Systems

The affected product is Oracle Time and Labor, part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15. No other vendors or product lines are listed as directly impacted.

Risk and Exploitability

The CVSS 3.1 base score of 6.6 indicates moderate severity, with confidentiality impact rated high and integrity impact low. The EPSS score of less than 1% suggests exploitation is unlikely but possible. The vulnerability is not listed in CISA KEV, yet the scope change indicates that attacks may also affect other Oracle E-Business Suite products. An attacker who has gained network access to the HTTP endpoint can exploit this flaw with high privileges, achieving unauthorized data manipulation.

Generated by OpenCVE AI on August 2, 2026 at 20:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Time and Labor patch released in the July 2026 CPU, which addresses this vulnerability.
  • Restrict HTTP access to Oracle Time and Labor to trusted internal hosts or VPN‑only connections to limit network exposure.
  • Enforce strict application‑level authentication and authorization controls and regularly audit permissions to prevent privilege misuse.

Generated by OpenCVE AI on August 2, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit in Oracle Time and Labor Allows Unauthorized Data Access

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Data Access via HTTP in Oracle Time and Labor
Weaknesses CWE-285

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Data Access via HTTP in Oracle Time and Labor
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. While the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data as well as unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:02:44.435Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61013

cve-icon Vulnrichment

Updated: 2026-07-24T15:02:34.181Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control