Executive brief
A vulnerability exists in the Internal Operations component of Oracle HR Intelligence, a tool used for human resources data analysis within the Oracle E-Business Suite. A high-privileged attacker could exploit this flaw to gain full control over the HR Intelligence system. This could lead to the unauthorized access, modification, or deletion of sensitive employee and organizational data.
Technical details
This vulnerability in Oracle HR Intelligence (Internal Operations component) is characterized by improper privilege management or access control (CWE-269, CWE-284). It is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle HR Intelligence product, impacting confidentiality, integrity, and availability. The issue affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Security patches are typically released through Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle HR Intelligence 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date