Description
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Tax Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker with a low‑privilege logon on the infrastructure where Oracle HRMS (US) executes to compromise the Payroll Tax Issues component of Oracle HRMS (US). Successful exploitation can lead to full takeover of the HRMS system, providing the attacker with complete access to confidential payroll data and the ability to manipulate or delete records. The CVSS 3.1 vector indicates local access, low authentication, and no user interaction, resulting in high confidentiality, integrity, and availability impact. The weakness is consistent with a local privilege escalation flaw, encompassed by CWE-284.

Affected Systems

Oracle Corporation’s Oracle HRMS (US) Payroll Tax Issues component of Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 are specifically listed as vulnerable. Users of these releases should review patch status for their environment.

Risk and Exploitability

The CVSS base score of 7.8 marks this as a high‑severity issue. With an EPSS score of < 1 % the likelihood of exploitation is low, yet the vulnerability remains potentially exploitable if the infrastructure is accessible to an attacker and a low‑privileged account exists. The likely attack vector is local; an adversary must have a valid user session on the host or be able to log‑in through a compromised account to leverage the flaw.

Generated by OpenCVE AI on August 20, 2026 at 23:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle HRMS (US) patch or upgrade beyond version 12.2.15.
  • Limit local user privileges and isolate HRMS processes from low‑privileged accounts.
  • Enable audit logging and monitor HRMS for unauthorized access or abnormal activity.
  • Implement network segmentation to restrict non‑trusted hosts from interacting with the HRMS infrastructure.

Generated by OpenCVE AI on August 20, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle human Resources Management System
CPEs cpe:2.3:a:oracle:human_resources_management_system:*:*:*:*:*:*:*:*
Vendors & Products Oracle human Resources Management System

Thu, 20 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Low‑Privilege Exploit Enables Full Oracle HRMS (US) Compromise

Thu, 20 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle HRMS (US) Payroll Tax Issues

Thu, 20 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle HRMS (US) Payroll Tax Issues
Weaknesses CWE-269

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Logon Allows Compromise of Oracle HRMS (US) Payroll Tax Component

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Logon Allows Compromise of Oracle HRMS (US) Payroll Tax Component
Weaknesses CWE-269

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Tax Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Hrms Human Resources Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:01:23.360Z

Reserved: 2026-08-04T22:06:34.617Z

Link: CVE-2026-71101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:10.380

Modified: 2026-08-25T19:02:49.340

Link: CVE-2026-71101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses