Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-07-21
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Time and Labor’s Internal Operations component allows an attacker who already has high privileges on the network to perform unauthorized creation, modification, or deletion of critical data. The flaw also permits full unauthorized access to all data stored in Oracle Time and Labor and can be used to induce a partial denial of service. The weakness results in high impact to confidentiality, integrity, and low impact to availability, as reflected by the CVSS‑3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).

Affected Systems

Oracle Time and Labor, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The issue resides in the Internal Operations component, which is exposed via HTTP and requires high‑level credentials to exploit.

Risk and Exploitability

The CVSS base score of 6.7 indicates a moderate to high risk. EPSS is below 1%, meaning current exploitation probability is very low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker who can reach the system over HTTP and who has high‑privilege credentials can immediately execute the flaw and gain unauthorized data access or cause service disruption. The required network access and elevated privileges reduce the attack surface, but once those prerequisites are met, the vulnerability is easily exploitable and has significant damage potential.

Generated by OpenCVE AI on August 4, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle E‑Business Suite patch for Oracle Time and Labor versions 12.2.3 through 12.2.15 as provided in the Oracle CPU July 2026 advisory
  • Restrict HTTP access to Oracle Time and Labor to trusted IP ranges or internal networks only
  • Require multi‑factor authentication for high‑privileged accounts that access Oracle Time and Labor

Generated by OpenCVE AI on August 4, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authorization bypass and partial denial of service in Oracle Time and Labor through internal operations

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Authorization bypass and partial denial of service in Oracle Time and Labor through internal operations

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title High Privilege Access Vulnerability in Oracle Time and Labor via HTTP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title High Privilege Access Vulnerability in Oracle Time and Labor via HTTP

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:41:38.320Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62503

cve-icon Vulnrichment

Updated: 2026-07-22T15:40:40.885Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses