Executive brief
A security vulnerability exists in the Norway Payroll component of Oracle E-Business Suite. This software is used by organizations to manage human resources and payroll processing specifically for Norwegian operations. A high-privileged user could exploit this flaw to gain unauthorized access to sensitive payroll data, potentially allowing them to view, modify, or delete records, which could impact financial accuracy and data privacy.
Technical details
This vulnerability affects the Norway Payroll component within Oracle HRMS (Norway), a part of the Oracle E-Business Suite. It is classified as an unauthorized data access and modification flaw. An attacker requires high privileges (PR:H) and network access via HTTP (AV:N) to exploit the vulnerability. Successful exploitation allows the attacker to read a subset of data and perform unauthorized updates, inserts, or deletes on accessible data. The vulnerability is easily exploitable (AC:L) once the necessary privileges are obtained. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle E-Business Suite (Oracle HRMS Norway) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-61036 was published to the NVD.