Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the likely attack vector is low‑privilege network access via HTTP. Oracle HRMS (UK) Payroll contains an improper access control flaw that lets a user with low privileges and network connectivity via HTTP gain unauthorized access to HR data and perform creation, deletion or modification operations. This results in loss of confidentiality and integrity of critical HR information, as the attacker can alter or delete records at will.

Affected Systems

The flaw affects Oracle HRMS (UK) versions 12.2.3 through 12.2.15, which are part of Oracle E‑Business Suite. These versions expose administrative interfaces over HTTP, and while the vulnerability is localized to HRMS, the vector can change scope, enabling attacks against other Oracle components that interact with HRMS data.

Risk and Exploitability

Based on the description, the likely attack vector is low‑privilege network access over HTTP. With a CVSS base score of 9.6, the vulnerability is rated Critical. The EPSS score of less than 1 % indicates a very low but non‑zero exploitation probability, and it is not yet listed in CISA’s KEV catalog. Successful exploitation requires only low‑privilege network access over HTTP and no user interaction, meaning an attacker can remotely modify critical HR data from outside the trusted network.

Generated by OpenCVE AI on August 4, 2026 at 00:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle HRMS (UK) security patch or upgrade to a fixed version as indicated in the referenced CPU alert.
  • Restrict HTTP traffic to HRMS to trusted hosts or users via network ACLs or firewall rules.
  • Enable and monitor audit logging for HRMS to detect unauthorized creation, deletion or modification activities.

Generated by OpenCVE AI on August 4, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unauthorized HRMS Data Modification via Low-Privilege HTTP Access

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized HRMS Data Modification via Low-Privilege HTTP Access

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:23:02.526Z

Reserved: 2026-07-14T14:54:48.740Z

Link: CVE-2026-62549

cve-icon Vulnrichment

Updated: 2026-07-22T13:22:55.470Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses