Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. While the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data as well as unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of Oracle Time and Labor allows an attacker who already has high privileges and network access via HTTP to compromise the application. The weakness is a failure of access control, as indicated by the CWE identifiers 269 and 284, meaning the system does not properly limit what authorized users can do. Exploitation can leak sensitive business data, give the attacker a view of all data the application can reach, and enable insert, update or delete actions on that data.

Affected Systems

The affected product is Oracle Time and Labor, part of Oracle E-Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable. A scope change in the CVE notes indicates that a successful attack could also impact other Oracle E-Business Suite products that interact with Time and Labor.

Risk and Exploitability

The CVSS 3.1 base score of 6.6 shows moderate severity with high confidentiality impact and low integrity impact, and no availability impact. The EPSS score of less than 1 % suggests exploitation is unlikely but possible. The vulnerability is not listed in CISA KEV. An attacker would need to reach the HTTP endpoint from within the network and possess high‑privilege credentials; from there, the flaw can be abused to read or alter any data the application is allowed to see or modify.

Generated by OpenCVE AI on August 12, 2026 at 11:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Time and Labor patch released in the July 2026 CPU, which addresses this vulnerability.
  • Restrict HTTP access to Oracle Time and Labor to trusted internal hosts or VPN‑only connections to limit network exposure.
  • Enforce strict application‑level authentication and authorization controls and regularly audit permissions to prevent privilege misuse.

Generated by OpenCVE AI on August 12, 2026 at 11:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit in Oracle Time and Labor Allows Unauthorized Data Access

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Exploit in Oracle Time and Labor Allows Unauthorized Data Access

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Data Access via HTTP in Oracle Time and Labor
Weaknesses CWE-285

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Data Access via HTTP in Oracle Time and Labor
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. While the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data as well as unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:02:44.435Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61013

cve-icon Vulnrichment

Updated: 2026-07-24T15:02:34.181Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:33.130

Modified: 2026-08-03T18:47:45.063

Link: CVE-2026-61013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T11:30:03Z

Weaknesses