Executive brief
A vulnerability exists in Oracle iRecruitment, a module within the Oracle E-Business Suite used by organizations to manage hiring and talent acquisition. An unauthenticated attacker can exploit this flaw over the network to gain unauthorized access to sensitive recruitment data. This could lead to the exposure of personal applicant information or proprietary internal hiring records, potentially resulting in privacy compliance violations and reputational damage.
Technical details
An information disclosure vulnerability exists in the Internal Operations component of Oracle iRecruitment (part of Oracle E-Business Suite). The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation enables the attacker to gain unauthorized access to critical data or complete access to all data accessible by the iRecruitment module. The vulnerability affects versions 12.2.3 through 12.2.15. While the specific CWE is not provided in the advisory, the CVSS vector indicates a high confidentiality impact with no impact on integrity or availability.
Affected products
- Oracle iRecruitment (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date