Junglewise Threat Intelligence

CVE-2026-61015: Oracle Time and Labor unauthorized data access in Internal Operations

CVE-2026-61015 · Severity: low · CVSS 3.7 · Published 2026-07-21

Technologies: Oracle Time and Labor. Vendors: Oracle Corporation, Oracle.

Executive brief

Oracle Time and Labor, a component of the Oracle E-Business Suite used for managing employee hours and workforce data, contains a security vulnerability in its Internal Operations component. An attacker could potentially gain unauthorized access to sensitive workforce information. While the risk of data exposure exists, the vulnerability is considered difficult to exploit and does not allow an attacker to modify data or shut down the service.

Technical details

This vulnerability exists within the Internal Operations component of Oracle Time and Labor (versions 12.2.3 through 12.2.15). It is classified as a low-severity issue because, although it can be reached over the network via HTTP without authentication, it is characterized by high attack complexity. A successful exploit results in an unauthorized 'read' impact, allowing the attacker to access a limited subset of data. There is no impact on data integrity or service availability. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Time and Labor 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats