Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Time and Labor in the Oracle E‑Business Suite contains a hard‑to‑exploit flaw in its internal operations component that allows an unauthenticated attacker to read a limited subset of data via HTTP. The vulnerability results in a confidentiality impact because sensitive information may be exposed without authentication or privilege escalation. The weakness is a classic information disclosure flaw, classified as CWE‑200.

Affected Systems

Oracle Time and Labor, part of the Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The flaw can be reached from external networks over standard HTTP, exposing the vulnerable interface to the internet.

Risk and Exploitability

The CVSS Base Score 3.7 indicates a low severity vulnerability. The EPSS score of less than 1 % and the absence of this vulnerability from the CISA KEV catalog suggest that exploitation is unlikely. However, the vulnerability does not require authentication and is reachable over HTTP, thus any Oracle Time and Labor instance exposed to the network may allow an attacker to read a subset of sensitive data.

Generated by OpenCVE AI on August 2, 2026 at 20:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether Oracle has issued a patch or advisory for this issue; if a fix is available, apply it.
  • Restrict external HTTP access to Oracle Time and Labor’s internal operations component, ideally by placing the service behind an application firewall or isolating it within a secure network segment.
  • Enable detailed logging for HTTP traffic to the internal operations component and monitor for suspicious requests, alerting on anomalous patterns.

Generated by OpenCVE AI on August 2, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Oracle Time and Labor Unauthenticated Read Vulnerability

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Read of Sensitive Data in Oracle Time and Labor 12.2.3‑12.2.15
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Read of Sensitive Data in Oracle Time and Labor 12.2.3‑12.2.15
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:54:49.183Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61015

cve-icon Vulnrichment

Updated: 2026-07-24T14:54:42.629Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor