Description
Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kong Payroll). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Hong Kong). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Hong Kong) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Hong Kong) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle HRMS ( Hong Kong) product includes a flaw that lets a low‑privileged attacker with network access over HTTP alter, delete, insert, or read data that should be protected. The vulnerability directly affects the confidentiality and integrity of HRMS data without impacting availability. The weakness is an access‑control issue that lets unauthorized users perform privileged operations that they should not be allowed to execute.

Affected Systems

Affected versions are Oracle HRMS ( Hong Kong) 12.2.13 through 12.2.15, part of Oracle E‑Business Suite’s Hong Kong Payroll component. This applies to installations of the Oracle HRMS ( Hong Kong) product that have not been patched to a newer release.

Risk and Exploitability

The CVSS base score of 5.4 indicates moderate risk; the system could suffer non‑critical confidentiality and integrity breaches. The EPSS score of less than 1% suggests that the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be over the HTTP interface, reachable from the network and feasible for an attacker with low privileges who can reach the HRMS service.

Generated by OpenCVE AI on August 4, 2026 at 01:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Use the Oracle HRMS ( Hong Kong) patch containing the fix released in the Oracle CPU July 2026 alert to upgrade affected installations from versions 12.2.13‑12.2.15 to a patched release.
  • If a patch is not immediately available, isolate the HRMS HTTP service behind a firewall or network segmentation rule that limits access to trusted IP ranges or the internal network only.
  • Review role‑based access controls to confirm that only authorized personnel can submit update, insert, or delete requests to the HRMS ( Hong Kong) database, and disable any legacy or elevated privileges that may bypass these checks.

Generated by OpenCVE AI on August 4, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read via HTTP in Oracle HRMS (Hong Kong)

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read via HTTP in Oracle HRMS (Hong Kong)

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read in Oracle HRMS via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Read in Oracle HRMS via HTTP

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kong Payroll). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Hong Kong). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Hong Kong) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Hong Kong) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:18:02.631Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61252

cve-icon Vulnrichment

Updated: 2026-07-22T19:17:58.872Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses