Executive brief
A vulnerability exists in Oracle Time and Labor, a component of the Oracle E-Business Suite used for managing employee hours and workforce data. A high-privileged attacker could exploit this flaw to gain unauthorized access to sensitive corporate data or modify existing records. Because the vulnerability involves a 'scope change,' an exploit could potentially allow the attacker to impact other integrated Oracle products beyond just the time-tracking system.
Technical details
This vulnerability affects the Internal Operations component of Oracle Time and Labor (versions 12.2.3 through 12.2.15). It is classified as difficult to exploit (High Attack Complexity) and requires High Privileges from the attacker. The attack vector is via the network over HTTP. A successful exploit results in a 'Scope Change' (S:C), meaning the attacker can impact components beyond the security scope of Oracle Time and Labor. Impact includes high confidentiality loss (unauthorized access to all data) and low integrity loss (unauthorized modification of some data). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle Time and Labor 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published