Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle HRMS (UK) allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical HR data without proper authorization. The flaw can also lead to a partial denial of service for the HRMS (UK) application, compromising availability. The weakness arises from insufficient enforcement of access controls, resulting in integrity and availability impacts.

Affected Systems

Vulnerable systems are Oracle HRMS (UK) components of Oracle E‑Business Suite, specifically the UK Payroll module. Affected supported versions range from 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 indicates a medium severity, and the EPSS score of less than 1 % shows a very low likelihood of exploitation as of the current data. The vulnerability is not listed in CISA KEV. It is likely exploitable by an attacker who can reach the HRMS HTTP endpoint and has minimal local privileges, enabling unauthorized data operations and service disruptions without elevated privileges.

Generated by OpenCVE AI on August 4, 2026 at 01:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle's security advisories or update catalog for a patch or recommended compensating controls for Oracle HRMS (UK) UK Payroll.
  • Restrict HTTP/HTTPS access to the HRMS (UK) endpoint to trusted networks and apply network segmentation or firewall rules to reduce exposure.
  • Enforce strict role‑based access controls so that only authorized personnel can modify critical HR data; review and tighten existing roles and permissions.
  • Monitor application logs for anomalous data changes or service interruptions and set up alerts to detect potential exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle HRMS UK Payroll via HTTP Access

Thu, 30 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle HRMS UK Payroll via HTTP Access

Mon, 27 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle HRMS (UK) via HTTP

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle HRMS (UK) via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:32:17.440Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61119

cve-icon Vulnrichment

Updated: 2026-07-23T19:32:13.646Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses