Description
Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (New Zealand) accessible data as well as unauthorized read access to a subset of Oracle HRMS (New Zealand) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle HRMS (New Zealand) has a vulnerability that permits a low‑privileged attacker with network access through the HTTP interface to modify, insert or delete certain HR data and read a subset of information. The flaw is reflected in the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) and indicates that confidentiality and integrity are affected. The impact can lead to unauthorized alteration and disclosure of employee data, which may affect operational integrity and regulatory compliance.

Affected Systems

The affected vendor is Oracle Corporation. The product is Oracle HRMS (New Zealand) within the Oracle E‑Business Suite, specifically the New Zealand Payroll component. Vulnerable releases span 12.2.3 through 12.2.15, as identified by the listed CPE.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 indicates moderate risk with low confidentiality and integrity impact and no availability impact. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalogue. Because the attack vector is via a network HTTP interface and only requires low privilege, the flaw is relatively easy to exploit once the target is reachable, but it presumes the attacker already has some level of network access to the HRMS environment.

Generated by OpenCVE AI on August 4, 2026 at 16:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU Jul 2026 security patch for the affected HRMS versions.
  • Limit HTTP access to the Oracle HRMS (New Zealand) environment to trusted internal networks or VPN connections.
  • Enforce strict role‑based access controls in HRMS to prevent low‑privileged users from performing update, insert, or delete operations on employee data.
  • Monitor HRMS logs for unusual data manipulation or access patterns as a complementary measure.

Generated by OpenCVE AI on August 4, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification and Disclosure via Oracle HRMS HTTP Interface
Weaknesses CWE-200
CWE-284

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Enables Unauthorized HR Data Modification in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-640

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Enables Unauthorized HR Data Modification in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-640

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Access in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Access in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (New Zealand) accessible data as well as unauthorized read access to a subset of Oracle HRMS (New Zealand) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:29:02.044Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61255

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control