Description
Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle US Federal Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle US Federal Human Resources accessible data as well as unauthorized read access to a subset of Oracle US Federal Human Resources accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and read in Oracle US Federal Human Resources via low‑privileged HTTP access
Action: Patch Now
AI Analysis

Impact

The Oracle US Federal Human Resources product, a component of Oracle E‑Business Suite, contains a flaw in its Internal Operations module that allows an attacker with only low privileges and network connectivity over HTTP to create, delete or modify critical data, as well as read a subset of that data. This vulnerability can lead to integrity loss and exposure of confidential information, as explicitly noted in Oracle’s advisory.

Affected Systems

Versions 12.2.3 through 12.2.15 of Oracle US Federal Human Resources are affected. The vulnerability is limited to Oracle Corporation’s product; no other vendors or applications are mentioned.

Risk and Exploitability

The CVSS base score of 7.1 indicates high severity due to low attack complexity and local privilege. The EPSS score of less than 1% suggests exploitation is currently rare, and the issue is not listed in CISA’s KEV catalog. Nevertheless, because the attack vector is network‑based over HTTP and requires only low privileges, the risk remains significant for systems exposed to potentially hostile networks, warranting prompt remediation.

Generated by OpenCVE AI on September 20, 2026 at 07:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Oracle US Federal Human Resources 12.2.3–12.2.15 as detailed in the Oracle security advisory
  • Restrict HTTP access to the Internal Operations component so only trusted hosts or internal networks can reach it
  • Enforce strict least‑privilege access controls for users interacting with the component
  • Implement network segmentation to isolate the vulnerable component from untrusted traffic

Generated by OpenCVE AI on September 20, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation Enables Unauthorized Data Modification in Oracle US Federal Human Resources
Weaknesses CWE-284
CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title HTTP Exploitable Privilege Escalation in Oracle US Federal Human Resources
Weaknesses CWE-276
CWE-862

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title HTTP Exploitable Privilege Escalation in Oracle US Federal Human Resources
Weaknesses CWE-276
CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle US Federal Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle US Federal Human Resources accessible data as well as unauthorized read access to a subset of Oracle US Federal Human Resources accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle us Federal Human Resources
CPEs cpe:2.3:a:oracle:us_federal_human_resources:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle us Federal Human Resources
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle Us Federal Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:20:20.105Z

Reserved: 2026-08-31T15:40:57.362Z

Link: CVE-2026-83484

cve-icon Vulnrichment

Updated: 2026-09-21T19:20:15.667Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:56.147

Modified: 2026-09-21T20:17:36.163

Link: CVE-2026-83484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses