Executive brief
A vulnerability exists in the Internal Operations component of Oracle's Human Resources Management System (HRMS) for Ireland, which is part of the E-Business Suite. This software is used by organizations to manage employee data, payroll, and HR compliance. If exploited, a highly privileged user could gain unauthorized access to sensitive HR information, potentially compromising employee privacy or corporate data integrity.
Technical details
This vulnerability affects the Internal Operations component of Oracle HRMS (Ireland) within Oracle E-Business Suite. It is classified as a low-severity information disclosure flaw. An attacker requires high privileges and network access via HTTP to exploit the vulnerability. The attack complexity is rated as high, suggesting that specific conditions or configurations must be met for a successful exploit. If successful, the attacker can achieve unauthorized read access to a limited subset of data accessible to the HRMS (Ireland) component. The issue is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Suite HRMS (Ireland) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.
- 2026-07-21: disclosed: CVE-2026-60950 was published to the NVD.