Description
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of Oracle HRMS (US) permits a low‑privileged attacker who can reach the system over HTTP to gain unauthorized access to sensitive information. The vulnerability does not affect integrity or availability but allows the attacker to read critical HR data or, in the worst case, all data exposed by the application. The weakness is an information disclosure (CWE‑200) combined with insufficient access control (CWE‑284).

Affected Systems

Oracle Corporation’s HRMS (US) component of Oracle E‑Business Suite, specifically versions 12.2.6 through 12.2.15, are vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a moderate impact. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based via HTTP, requiring only low privileges on the network. The risk to organizations depends on the exposure of the HRMS application to the network and the sensitivity of the data it handles. Organizations with publicly accessible HRMS services face a higher risk than those that restrict access to internal networks.

Generated by OpenCVE AI on August 4, 2026 at 00:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for HRMS (US) to upgrade to a fixed version (12.2.16 or later).
  • Restrict HTTP access to the HRMS Internal Operations component, allowing only trusted internal IP ranges or VPN connections.
  • Enforce strict role‑based access controls and require strong authentication for all HRMS users.

Generated by OpenCVE AI on August 4, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle HRMS (US)

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle HRMS (US)

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Oracle HRMS (US) Low-Privilege HTTP Access Leads to Unauthorized Data Disclosure

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Oracle HRMS (US) Low-Privilege HTTP Access Leads to Unauthorized Data Disclosure

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:23:59.525Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62556

cve-icon Vulnrichment

Updated: 2026-07-22T13:23:51.731Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control