Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data as well as unauthorized read access to a subset of Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker that can reach Oracle HRMS (UK) over HTTP can perform unauthorized updates, inserts, or deletes, read restricted data, and trigger a partial denial of service. The flaw stems from information exposure (CWE‑200), privilege escalation (CWE‑269), and missing authorization controls (CWE‑284) that together grant confidentiality, integrity, and availability damage reflected in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L.

Affected Systems

The affected component is Oracle HRMS (UK) within Oracle E‑Business Suite, specifically supported versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS v3.1 score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests that the risk of exploitation is currently low. The vulnerability is not listed in CISA’s KEV catalog. However, the low attack complexity and requirement for only network access over HTTP mean that a malicious actor can reach the target within a corporate network and exploit the flaw if it remains unpatched.

Generated by OpenCVE AI on August 4, 2026 at 00:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official security patch for CVE-2026-62453 or upgrade to a release newer than 12.2.15
  • Limit HTTP access to Oracle HRMS (UK) to trusted IP ranges or internal networks
  • Enforce least‑privilege and proper role‑based access controls so that only authorized users can perform updates, deletes, or reads, and actively monitor logs for suspicious database activity

Generated by OpenCVE AI on August 4, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Modifications in Oracle HRMS (UK)

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Modifications in Oracle HRMS (UK)

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Exploitation in Oracle HRMS (UK) Allows Data Modification and Partial Denial of Service

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Exploitation in Oracle HRMS (UK) Allows Data Modification and Partial Denial of Service

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data as well as unauthorized read access to a subset of Oracle HRMS (UK) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HRMS (UK). CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:33:35.216Z

Reserved: 2026-07-14T14:54:48.732Z

Link: CVE-2026-62453

cve-icon Vulnrichment

Updated: 2026-07-22T17:33:31.400Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control