Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Oracle HRMS (UK) component of Oracle E‑Business Suite that allows an attacker with low privileges and network access over HTTP to bypass access controls and disclose sensitive payroll data. The weakness is rooted in improper authentication and information disclosure, enabling an attacker to obtain confidential data or, depending on the scope change, potentially full access to all HRMS (UK) data.

Affected Systems

Oracle HRMS (UK) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, are affected. These versions expose the vulnerability over the network via HTTP, and they may impact other related products due to a scope change.

Risk and Exploitability

The CVSS v3.1 score of 7.7 indicates a high risk to confidentiality, with attackers needing only network access and low privilege to succeed. The EPSS score of less than 1% suggests that exploitation is presently unlikely, and the vulnerability is not listed in CISA KEV. However, because the attack vector is plain HTTP and the vulnerability relies on weak authentication, a determined adversary could obtain access and potentially expand the attack scope to other components.

Generated by OpenCVE AI on August 4, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch or upgrade to a version newer than 12.2.15 that fixes the HRMS (UK) vulnerability.
  • Restrict HTTP/HTTPS access to the HRMS (UK) application by using firewalls or network segmentation so that only trusted IP ranges can reach the service.
  • Enforce least‑privilege for HRMS user accounts, disable unused accounts, and implement strong authentication to limit potential exploitation.
  • Enable detailed logging of HRMS access and monitor for abnormal activity patterns that may indicate an attempted exploitation.

Generated by OpenCVE AI on August 4, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthorized HRMS (UK) Data Disclosure via Unauthenticated HTTP Access

Thu, 30 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HRMS (UK) Data Disclosure via Unauthenticated HTTP Access

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit in Oracle HRMS (UK) Grants Extensive Data Access

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit in Oracle HRMS (UK) Grants Extensive Data Access

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:09:59.043Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62567

cve-icon Vulnrichment

Updated: 2026-07-22T13:09:52.882Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control