Description
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HCM Configuration Workbench accessible data as well as unauthorized read access to a subset of Oracle HCM Configuration Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle HCM Configuration Workbench vulnerability permits a low‑privileged attacker with network access via HTTP to perform unauthorized insert, update, or delete operations on configuration data, to read restricted data subsets, and to trigger a partial denial of service. The weakness involves improper access control, SQL injection, and information exposure (CWE‑284, CWE‑89, CWE‑200).

Affected Systems

Affected vendors are Oracle Corporation, specifically the Oracle HCM Configuration Workbench component of Oracle E-Business Suite. The vulnerability impacts versions ranging from 12.2.3 through 12.2.15.

Risk and Exploitability

With a CVSS 3.1 base score of 6.3 and an EPSS score of less than 1 %, the exploitation probability is low but not negligible. The vulnerability is not listed in the CISA KNOWN EXPLOITED VULNERABILITIES catalog. The likely attack vector is HTTP requests sent to the configuration web interface, requiring only a low‑privilege account but granting significant read/write privileges and the ability to disrupt service.

Generated by OpenCVE AI on August 4, 2026 at 00:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 Oracle patch that addresses the HCM Configuration Workbench vulnerability.
  • Limit HTTP access to the configuration interface to trusted networks or a VPN, using firewall or VLAN rules.
  • Enforce least‑privilege permissions for all users interacting with the configuration workbench, ensuring they only have the minimum rights required.

Generated by OpenCVE AI on August 4, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle HCM Configuration Workbench via HTTP

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle HCM Configuration Workbench via HTTP

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low-Privilege HTTP Attack

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low-Privilege HTTP Attack

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-89
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HCM Configuration Workbench accessible data as well as unauthorized read access to a subset of Oracle HCM Configuration Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle hcm Configuration Workbench
CPEs cpe:2.3:a:oracle:hcm_configuration_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hcm Configuration Workbench
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Hcm Configuration Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:49:10.653Z

Reserved: 2026-07-14T14:54:48.739Z

Link: CVE-2026-62528

cve-icon Vulnrichment

Updated: 2026-07-22T13:48:46.223Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')