Executive brief
A vulnerability exists in Oracle HR Intelligence, a component of the Oracle E-Business Suite used for human resources data analysis and reporting. A high-privileged user could exploit this flaw over the network to gain full control of the HR Intelligence system. This could lead to the unauthorized access, modification, or deletion of sensitive employee data and organizational records.
Technical details
A vulnerability in the Internal Operations component of Oracle HR Intelligence (Oracle E-Business Suite) allows for improper privilege management (CWE-269). The flaw affects versions 12.2.3 through 12.2.15. An attacker with high-level administrative privileges can exploit this vulnerability via HTTP over a network without any user interaction. Successful exploitation results in a complete takeover of the Oracle HR Intelligence component, impacting the confidentiality, integrity, and availability of the system. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle HR Intelligence 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory