Description
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle HRMS (US) permits a low‑privileged attacker with network access via HTTP to bypass or circumvent access controls and obtain sensitive data. The vulnerability is rated CVSS 3.1 with a base score of 6.5 and primarily affects confidentiality.

Affected Systems

Systems running Oracle HRMS (US) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are impacted. Affected installations expose the internal operations component to HTTP traffic.

Risk and Exploitability

The attack vector is an HTTP endpoint, requiring low privileged credentials. While the EPSS score is less than 1% indicating low current exploitation probability, the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 6.5 highlights a medium severity risk with potential unauthorized data exposure. No additional prerequisites beyond network access to the HRMS HTTP interface are described.

Generated by OpenCVE AI on August 4, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch for Oracle HRMS (US) versions 12.2.3–12.2.15
  • Restrict HTTP access to the HRMS internal operations component to trusted IP ranges or internal network segments
  • Enforce session management best practices such as short session timeouts and explicit logout, ensuring least privilege for account types
  • Enable and regularly review audit logs for failed authentication attempts to detect potential exploitation

Generated by OpenCVE AI on August 4, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP Attack on Oracle HRMS

Sun, 02 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege HTTP Attack on Oracle HRMS

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Control Bypass in Oracle HRMS (US)

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Control Bypass in Oracle HRMS (US)

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:12:58.543Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62562

cve-icon Vulnrichment

Updated: 2026-07-22T13:12:54.893Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses