Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data as well as unauthorized read access to a subset of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A defect in Oracle HRMS (UK) allows a low‑privileged attacker who can reach the application over HTTP to alter data—perform updates, inserts, or deletes—and to read data that should be protected. This is a CWE‑284: Improper Authorization vulnerability. The flaw does not affect availability but can compromise the confidentiality and integrity of HRMS data.

Affected Systems

Oracle HRMS (UK) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 indicates moderate severity with low confidentiality and integrity impact. The EPSS score of fewer than 1% shows the likelihood of exploitation is low. Oracle HRMS (UK) is not listed in the CISA KEV catalog. The vulnerability can be exploited by any attacker who has network access to the HRMS HTTP interface with no elevated privileges, typically by sending crafted HTTP requests to the payroll component.

Generated by OpenCVE AI on August 4, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or update released by Oracle in the July 2026 CPU advisory
  • Restrict HTTP access to Oracle HRMS (UK) to trusted internal networks or known IP ranges to limit potential attackers
  • Ensure that HRMS access controls enforce proper authorization for update, insert, and delete operations and that users have only the permissions required for their roles
  • Enable and review monitoring for anomalous data modification or read attempts within HRMS for rapid detection

Generated by OpenCVE AI on August 4, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Authorization Breach in Oracle HRMS UK Payroll

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Data Modification and Disclosure via HTTP in Oracle HRMS (UK)

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Data Modification and Disclosure via HTTP in Oracle HRMS (UK)

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data as well as unauthorized read access to a subset of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:20:46.672Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61260

cve-icon Vulnrichment

Updated: 2026-07-22T15:20:41.574Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses