Description
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Human Resources executes to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Human Resources’ Enterprise Command Center component allows a low‑privileged user who can log on to the host operating system to create, delete, or modify critical HR data. The vulnerability gives the attacker unauthorized access to all data that the application normally protects, impacting both confidentiality and integrity. The flaw is classified as a local–access control issue (CWE‑284), exposing the system to changes of information that could be used for fraud, identity theft, or disruption of HR processes.

Affected Systems

Oracle Human Resources, part of Oracle E‑Business Suite, is affected. Supported versions 12.2.14 and 12.2.15 contain the flaw. Users running either of these releases should verify whether their installations include this component and assess exposure.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates a medium‑to‑high severity, with high confidentiality and integrity impact. The EPSS score of less than 1% suggests a low probability of imminent widespread exploitation, and the vulnerability is not listed in CISA KEV. Nevertheless, because the attack requires only local access and low privilege, any insider or compromised account that can log into the HR server can exercise the flaw. The lack of a user interaction requirement makes it easy to exploit for an attacker in control of the host.

Generated by OpenCVE AI on August 4, 2026 at 00:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle Human Resources patches for versions 12.2.14 and 12.2.15 as soon as they become available
  • Restrict local user accounts on HR servers to the minimum set required for operation and remove or disable unused accounts
  • Limit network access to the HR servers using segmentation or firewall rules to block lateral movement
  • Enable logging of all HR data modification operations and monitor logs for unauthorized activity

Generated by OpenCVE AI on August 4, 2026 at 00:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Vulnerability in Oracle Human Resources Enables Unauthorized Data Modification by Low-Privileged Users

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local Vulnerability in Oracle Human Resources Enables Unauthorized Data Modification by Low-Privileged Users

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Human Resources Allows Data Modification

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Human Resources Allows Data Modification

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Enterprise Command Center). Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Human Resources executes to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle human Resources
CPEs cpe:2.3:a:oracle:human_resources:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle human Resources
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:14:58.796Z

Reserved: 2026-07-14T14:54:48.733Z

Link: CVE-2026-62469

cve-icon Vulnrichment

Updated: 2026-07-22T16:14:53.794Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses