Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle HRMS (UK) component of Oracle E‑Business Suite – specifically the UK Payroll module – permits a low‑privileged attacker with network access via HTTP to read and modify protected HR data. The vulnerability, classified as an authorization flaw (CWE‑284), enables disclosure of confidential information and integrity violations such as unauthorized updates, inserts, or deletions of critical HR records.

Affected Systems

Oracle Corporation’s Oracle HRMS (UK) component of the E‑Business Suite is affected for all supported releases from version 12.2.3 through 12.2.15. Any system running one of these releases must be inspected to confirm vulnerability status.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 indicates a high severity rating, while the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low but non‑zero exploitation probability. The attack vector is network delivery over HTTP; a low‑privileged user can exploit the issue remotely without authentication, making the risk significant for exposed services.

Generated by OpenCVE AI on August 4, 2026 at 00:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that resolves CVE‑2026‑62557 to all affected HRMS (UK) instances.
  • Restrict HTTP access to the HRMS (UK) service by configuring firewall rules or enforcing VPN usage so only trusted networks can reach the application.
  • Enable detailed audit logging on HRMS (UK) to track unauthorized read or modify activity and review logs regularly.

Generated by OpenCVE AI on August 4, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Authorization Flaw in Oracle HRMS (UK) Payroll Allows Low-Privileged Remote Access

Sun, 02 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Authorization flaw allows unauthorized HR data access in Oracle HRMS UK Payroll

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Authorization flaw allows unauthorized HR data access in Oracle HRMS UK Payroll

Mon, 27 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle HRMS (UK) via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle HRMS (UK) via HTTP

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:40:24.424Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62557

cve-icon Vulnrichment

Updated: 2026-07-22T13:40:20.922Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses