Description
Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Human Resources accessible data as well as unauthorized read access to a subset of Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Regression Testing component of Oracle Public Sector Human Resources and represents an authorization weakness (CWE-284). It allows an attacker with low‑level privileges to interact over HTTP and perform unauthorized insert, update, or delete operations, as well as read selected data. This grants the attacker both integrity and confidentiality impact as reflected in the CVSS 5.4 score.

Affected Systems

Oracle Public Sector Human Resources versions 12.2.3 through 12.2.15 are affected. The product is offered by Oracle Corporation as part of its E‑Business Suite for public‑sector human‑resources applications.

Risk and Exploitability

The CVSS Base Score of 5.4 indicates a moderate severity, with the EPSS score below 1% and no listing in the CISA KEV catalog. The likely attack vector is a low‑privileged user that can reach the application via HTTP on the network. Successful exploitation requires only network access and results in unauthorized data modification or exfiltration, making it a potentially useful tool for a threat actor with modest capabilities.

Generated by OpenCVE AI on August 4, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle‑published security patch or upgrade to a version newer than 12.2.15 that removes this vulnerability.
  • Restrict HTTP access to the Oracle Public Sector Human Resources application to trusted hosts or through a VPN so that only authorized personnel can reach it.
  • Enforce strict role‑based access control so that low‑privileged accounts cannot perform insert, update, or delete operations on sensitive data.

Generated by OpenCVE AI on August 4, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Public Sector Human Resources via Regression Testing Component

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Public Sector Human Resources Allows Unauthorized Data Modification and Read Access

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Public Sector Human Resources Allows Unauthorized Data Modification and Read Access

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title HTTP Access Allows Low‑Privilege Data Modification in Oracle Public Sector Human Resources

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title HTTP Access Allows Low‑Privilege Data Modification in Oracle Public Sector Human Resources

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Public Sector Human Resources accessible data as well as unauthorized read access to a subset of Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle public Sector Human Resources
CPEs cpe:2.3:a:oracle:public_sector_human_resources:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Human Resources
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Public Sector Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T13:55:51.035Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61080

cve-icon Vulnrichment

Updated: 2026-07-24T13:55:44.676Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses