Description
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle HRMS (US) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (US). CVSS 3.1 Base Score 4.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).
Published: 2026-07-21
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle HRMS (US) allows a low‑privileged attacker with network access via HTTP to exploit a defect that is difficult to trigger. Successful exploitation results in unauthorized reading of a subset of the HRMS data and the ability to cause a partial denial of service for the HRMS (US) component. The impact is limited to confidentiality and availability, reflected in a CVSS 3.1 base score of 4.2.

Affected Systems

Oracle Corporation’s Oracle HRMS (US) component “Internal Operations,” affecting all supported releases from version 12.2.3 through 12.2.15. Network access to the HTTP interface of this product is required to reach the vulnerable code.

Risk and Exploitability

The CVSS score of 4.2 indicates a moderate severity level. EPSS is reported as < 1 %, meaning that the likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a HTTP requests to the HRMS (US) service. Successful exploitation requires the attacker to hit the specific vulnerable path and is mitigated by proper access control and network segmentation.

Generated by OpenCVE AI on August 2, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle‑supplied patch or update that addresses CVE‑2026‑61123 for the affected HRMS (US) versions
  • Restrict HTTP access to the HRMS (US) instance to a narrow set of trusted IP addresses for unauthorized read attempts and configure alerts for anomalous activity
  • Implement network segmentation and monitor logs for abnormal activity to detect potential exploitation attempts

Generated by OpenCVE AI on August 2, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Read Access and Partial Denial of Service in Oracle HRMS (US)
Weaknesses CWE-284

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Read Access and Partial Denial of Service in Oracle HRMS (US)
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle HRMS (US) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (US). CVSS 3.1 Base Score 4.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:33:35.241Z

Reserved: 2026-07-08T15:51:55.614Z

Link: CVE-2026-61123

cve-icon Vulnrichment

Updated: 2026-07-23T19:33:31.091Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-400

    Uncontrolled Resource Consumption