Executive brief
A vulnerability exists in the Oracle HCM Configuration Workbench, a tool used within the Oracle E-Business Suite for human resources management and system setup. A high-privileged user can exploit this flaw over the network to gain full control of the workbench component. This could lead to the unauthorized access, modification, or deletion of sensitive HR data and disruption of business operations.
Technical details
This vulnerability affects the Rapid Implementation component of Oracle HCM Configuration Workbench within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires high-privileged credentials to execute. An attacker with network access via HTTP can leverage this vulnerability to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the impact is described as a full system compromise. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle HCM Configuration Workbench 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD entry published