Executive brief
Oracle Labor Distribution, a component of the Oracle E-Business Suite used for managing payroll and labor costs, contains a security vulnerability in its Internal Operations component. A low-privileged user could exploit this flaw to disrupt the application's availability, leading to a partial denial of service. While difficult to execute, a successful attack could hinder business operations and payroll processing tasks.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Labor Distribution (versions 12.2.3 through 12.2.15). The flaw is accessible via HTTP over a network and requires low-privileged authentication to exploit. It is characterized by high attack complexity, suggesting specific timing or environmental conditions are necessary for success. An attacker successfully exploiting this vulnerability can cause a partial denial of service (DoS), impacting the availability of the Labor Distribution module. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Labor Distribution 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory