Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Time and Labor product in the Internal Operations component contains an authorization bypass flaw that permits a low‑privileged attacker with HTTP network access to create, delete, or modify critical data. An attacker who can reach the application over HTTP can also gain unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. This leads to confidentiality and integrity compromise, as reflected by a CVSS vector with high confidentiality and high integrity impacts.

Affected Systems

Affected installations are Oracle Time and Labor releases version 12.2.3 through 12.2.15. Versions outside this range are not documented as affected in the current advisory.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high‑severity vulnerability with significant confidentiality and integrity impacts. The EPSS score of less than 1% suggests a low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request from an attacker who has low‑privileged access to the system. Successful exploitation requires the attacker to be able to send HTTP traffic to the vulnerable service.

Generated by OpenCVE AI on August 4, 2026 at 00:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or update for the affected Oracle Time and Labor versions (12.2.3‑12.2.15) to remediate the vulnerability.
  • Restrict HTTP exposure by limiting access to trusted networks or enforcing VPN connectivity.
  • Apply network segmentation and monitor for anomalous data modification activity.

Generated by OpenCVE AI on August 4, 2026 at 00:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Time and Labor Allows Data Modification and Unauthorized Access

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Time and Labor Allows Data Modification and Unauthorized Access

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Time and Labor

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Time and Labor

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data as well as unauthorized access to critical data or complete access to all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:42:18.447Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62504

cve-icon Vulnrichment

Updated: 2026-07-22T15:42:15.242Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses