Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle Time and Labor allows a low-privileged attacker who can reach the application over HTTP to create, delete or modify critical data. The flaw stems from an improper access-control check (CWE-284) that lets the attacker bypass authorization requirements when exercising operations on internal data. Successful exploitation would not provide code execution or denial of service; it would specifically compromise the integrity of data that the application processes.

Affected Systems

Oracle Time and Labor component Internal Operations for Oracle E-Business Suite versions 12.2.3 through 12.2.15 are impacted. All installations of these versions should be verified for the issue.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate impact exclusively on integrity. The EPSS score is reported as < 1%, meaning the likelihood of exploitation is very low and the vulnerability is not listed in the CISA KEV catalog. The attack route requires network access over HTTP, low-privilege authentication, and exploitation of the missing authorization check. Because the vulnerability does not provide remote code execution or privilege escalation beyond the attacker’s existing level, the overall risk remains moderate but should still be addressed promptly.

Generated by OpenCVE AI on August 4, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Time and Labor to a non‑affected version such as 12.2.16 or later, following the Oracle CPU July 2026 advisory.
  • Restrict HTTP access to the application to trusted network ranges and enforce strong authentication before permitting any data‑manipulation requests.
  • Enable and monitor auditing on data modification operations to detect and investigate potential unauthorized activity.

Generated by OpenCVE AI on August 4, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Bypass in Oracle Time and Labor Enables Data Modification

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Bypass in Oracle Time and Labor Enables Data Modification

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege Network Attack on Oracle Time and Labor

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege Network Attack on Oracle Time and Labor

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Time and Labor accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:22:35.666Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62507

cve-icon Vulnrichment

Updated: 2026-07-22T15:22:30.420Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses