Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle HRMS (UK), part of Oracle E-Business Suite, contains a vulnerability that enables an attacker with low privileges and network access to issue HTTP requests that return confidential application data. The flaw is classed as an information disclosure and authorization bypass weakness, which permits read-only access to all data exposed by the HRMS module without needing valid user credentials. No impact on data integrity or availability is described.

Affected Systems

Affected releases range from 12.2.8 through 12.2.15. These versions include the Internal Operations component of Oracle HRMS (UK). Any installation of these releases that listens for HTTP traffic is vulnerable, regardless of operating system or additional Oracle components deployed alongside.

Risk and Exploitability

The CVSS 3.1 base score of 6.3 indicates moderate severity, with high attack complexity and low privileges required, and no user interaction. The EPSS score of less than 1 % suggests a very low probability of public exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The descriptive note that the scope changes implies that a successful compromise may affect ancillary Oracle products, expanding the overall attack surface. The most likely attack vector is remote over the network via HTTP, as indicated by the vector string AV:N.

Generated by OpenCVE AI on August 4, 2026 at 01:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 update for Oracle HRMS (UK) as per the official security alert
  • Restrict HTTP access to the HRMS server by configuring firewall rules to allow only trusted networks or IP addresses
  • Monitor authentication logs and unexpected data access patterns for signs of exploitation attempts and consider implementing additional logging or alerting on HRMS API endpoints

Generated by OpenCVE AI on August 4, 2026 at 01:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-privilege HTTP Information Disclosure in Oracle HRMS (UK)

Sun, 02 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Access Leads to Unauthorized Data Exposure in Oracle HRMS (UK)

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Access Leads to Unauthorized Data Exposure in Oracle HRMS (UK)

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Remote Data Access via HTTP in Oracle HRMS (UK)

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Remote Data Access via HTTP in Oracle HRMS (UK)

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:36:40.828Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61117

cve-icon Vulnrichment

Updated: 2026-07-23T19:36:35.320Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control