Description
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle HRMS (US) in the Oracle E‑Business Suite contains a vulnerability that allows a high‑privileged attacker with HTTP network access to read all data that the user can normally access. The flaw, documented as affecting versions 12.2.3 through 12.2.15, can lead to an unauthorized disclosure of confidential business information. The weakness maps to CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).

Affected Systems

Version 12.2.3 to 12.2.15 of Oracle HRMS (US) within the Oracle E‑Business Suite, particularly the Internal Operations component, is impacted. Because the CVE notes a scope change, other related products in the suite may also be affected.

Risk and Exploitability

The CVSS v3.1 base score of 6.8 designates this vulnerability as medium severity with a primary confidentiality impact. The EPSS score of less than 1 % signals a low likelihood of exploitation in the wild, and it is not currently listed in CISA’s KEV catalog. The likely attack vector is over HTTP, and it requires that the adversary already possess high‑privileged credentials or obtain them through an unrelated compromise. If exploited, the attacker can access all HRMS (US) data visible to that account, potentially exposing sensitive employee and financial information.

Generated by OpenCVE AI on August 4, 2026 at 00:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle HRMS (US) update from the CPU July 2026 patch set.
  • Restrict HTTP access to the HRMS (US) application by configuring firewalls and network segmentation.
  • Enforce least‑privilege on high‑privileged accounts and monitor for unusual activity.

Generated by OpenCVE AI on August 4, 2026 at 00:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via High‑Privilege HTTP in Oracle HRMS (US)

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Attack Grants Unauthorized Data Access in Oracle HRMS (US)

Mon, 27 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Attack Grants Unauthorized Data Access in Oracle HRMS (US)

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:42:34.817Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62559

cve-icon Vulnrichment

Updated: 2026-07-22T13:42:02.931Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control