Description
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). While the vulnerability is in Oracle HRMS (Norway), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (Norway) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access to the HTTP interface of Oracle HRMS (Norway) can exploit an access‑control flaw to read all data stored in the system. The weakness is linked to insufficient authentication checks and inadequate separation of privileges, as reflected in CWE‑200 and CWE‑284. The flaw also carries a scope change, indicating that exploitation may affect other components of the Oracle E‑Business Suite as well.

Affected Systems

Oracle HRMS (Norway), part of Oracle E‑Business Suite Internal Operations, is affected for versions 12.2.3 through 12.2.15. The product is accessed over HTTP and distributed by Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 classifies the vulnerability as high severity. An EPSS score of less than 1 % signals that exploitation is currently considered unlikely. The flaw is not listed in the CISA KEV catalog. An attacker requires only network connectivity to the HTTP and a low‑privilege account to read sensitive data, making the attack path relatively straightforward.

Generated by OpenCVE AI on August 4, 2026 at 00:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for HRMS (Norway) released in the July 2026 CPU update.
  • Restrict HTTP access to the HRMS system to a trusted set of IP addresses using firewall or ACL rules.
  • Review and tighten role‑based access controls to ensure low‑privileged users do not possess permissions that could bypass authorization checks.

Generated by OpenCVE AI on August 4, 2026 at 00:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Oracle HRMS (Norway) Inadequate Access Control Allows Unauthorized Data Access via HTTP

Sun, 02 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Oracle HRMS (Norway) Inadequate Access Control Allows Unauthorized Data Access via HTTP

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low‑Privilege Network Attacker

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low‑Privilege Network Attacker

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). While the vulnerability is in Oracle HRMS (Norway), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (Norway) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:07:44.907Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62560

cve-icon Vulnrichment

Updated: 2026-07-22T13:07:39.998Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control