Description
Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Service). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An information‑exposure flaw resides in the Manager Self‑Service component of Oracle Self‑Service Human Resources, classified as CWE‑200. The weakness permits a low‑privilege attacker who can reach the HTTP interface to read data that should not be exposed to that user, potentially providing full access to all data available through the system. The CVSS 3.1 base score of 6.5 reflects a high impact on confidentiality while integrity and availability remain unaffected.

Affected Systems

The vulnerability affects Oracle Self‑Service Human Resources of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, when the Manager Self‑Service feature is deployed. Administrators should verify whether their installations fall within this version range and include the affected component.

Risk and Exploitability

Although the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, the attack can be executed over the network via HTTP and only requires low‑privilege credentials. This combination of a network‑based exploitation path and minimal privilege requirement raises the risk of confidential data exposure for any system that permits HTTP access to the Manager Self‑Service endpoint, making confidentiality the primary concern.

Generated by OpenCVE AI on August 4, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Self‑Service Human Resources patch available through the Oracle Support portal; consult the most recent CPU release for versions 12.2.3–12.2.15.
  • Restrict HTTP access to the Manager Self‑Service endpoint by using network segmentation or firewall rules so that only trusted administrative hosts can reach it.
  • Enforce least‑privilege policies on all accounts that interact with Self‑Service Human Resources, ensuring only the permissions required for their role are granted.

Generated by OpenCVE AI on August 4, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Low‑Privilege HTTP Access in Oracle Self‑Service Human Resources

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Low‑Privilege HTTP Access in Oracle Self‑Service Human Resources

Mon, 27 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure in Oracle Self‑Service Human Resources Manager Self‑Service

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure in Oracle Self‑Service Human Resources Manager Self‑Service

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Manager Self-Service). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle self-service Human Resources
CPEs cpe:2.3:a:oracle:self-service_human_resources:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle self-service Human Resources
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Self-service Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:15:35.907Z

Reserved: 2026-07-14T14:54:48.733Z

Link: CVE-2026-62470

cve-icon Vulnrichment

Updated: 2026-07-22T16:15:31.526Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor