Description
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a resource exhaustion flaw in the Internal Operations component of Oracle Time and Labor, part of Oracle E‑Business Suite. It allows a low‑privilege attacker who can reach the application over HTTP to exploit the flaw and cause a partial denial of service. The weakness is identified as CWE‑400 and results in degraded availability of the application, but does not expose confidential data or alter integrity. The impact is confined to the affected Oracle Time and Labor instance and is limited to a reduction or interruption of service availability.

Affected Systems

Oracle Time and Labor versions 12.2.3 through 12.2.15 are affected. The flaw exists within the Internal Operations component of the Oracle E‑Business Suite product and applies to systems deployed with these version ranges.

Risk and Exploitability

The CVSS base score of 3.1 indicates a low severity impact on availability, and the EPSS score of less than 1% signals a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, reinforcing its low exposure. An attacker would need network access to the application’s HTTP interface and only require low privileges to launch an attack that could degrade availability.

Generated by OpenCVE AI on August 4, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch that fixes CVE‑2026‑62508
  • Restrict network access to the Oracle Time and Labor HTTP interface to authorized users only, using firewall or access‑control rules
  • Monitor and alert on abnormal request rates or excessive resource consumption to detect potential denial‑of‑service activity

Generated by OpenCVE AI on August 4, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Enables Partial Denial of Service in Oracle Time and Labor

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Enables Partial Denial of Service in Oracle Time and Labor

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service in Oracle Time and Labor via Low-Privilege HTTP Access

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Partial Denial of Service in Oracle Time and Labor via Low-Privilege HTTP Access

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Time and Labor. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle time And Labor
CPEs cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle time And Labor
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Time And Labor
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:23:48.498Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62508

cve-icon Vulnrichment

Updated: 2026-07-22T15:23:32.691Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption