Description
Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Self-Service Human Resources accessible data as well as unauthorized read access to a subset of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle Self‑Service Human Resources is an access control weakness (CWE‑284) that allows a low‑privileged attacker who can reach the application over HTTP to perform unauthorized update, insert, or delete operations, and read a subset of HR data. Successful exploitation results in loss of data integrity for HR records and authorized disclosure of confidential personnel information. The vulnerability is limited to the internal Operations component of Oracle E‑Business Suite and does not provide code execution or denial‑of‑service capabilities.

Affected Systems

Oracle Self‑Service Human Resources component of Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Any installation of these releases that exposes the application to the HTTP interface over a network is vulnerable. The exposure can include public‑facing or internal LAN nodes reachable by an attacker with low network privileges.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 indicates moderate severity. The EPSS score of less than 1% signals a very low probability of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. Exploitation requires only network connectivity to the exposed HTTP service and does not require elevated privileges or authentication; a low‑privileged user account or unauthenticated access via the HTTP interface is sufficient. No remote code execution is possible, but the ability to modify or read HR data can have significant operational impact.

Generated by OpenCVE AI on August 4, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Self‑Service Human Resources or upgrade to a release newer than 12.2.15.
  • Restrict access to the Self‑Service Human Resources HTTP interface to trusted hosts or networks by configuring firewall or reverse‑proxy rules.
  • Monitor HR data access logs and database change logs to detect unauthorized insert, update, or delete operations.

Generated by OpenCVE AI on August 4, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Bypass in Oracle Self‑Service Human Resources

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Bypass in Oracle Self‑Service Human Resources

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Data Access in Oracle Self‑Service Human Resources

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Data Access in Oracle Self‑Service Human Resources

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Self-Service Human Resources accessible data as well as unauthorized read access to a subset of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle self-service Human Resources
CPEs cpe:2.3:a:oracle:self-service_human_resources:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle self-service Human Resources
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Self-service Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:08:55.001Z

Reserved: 2026-07-08T15:51:55.611Z

Link: CVE-2026-61075

cve-icon Vulnrichment

Updated: 2026-07-24T14:08:49.197Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses