Executive brief
A vulnerability exists in the Internal Operations component of Oracle Self-Service Human Resources, a tool used by employees to manage their personal and employment information. An attacker with basic user credentials could exploit this flaw to view, modify, or delete certain HR-related data. This could lead to unauthorized changes to employee records or the exposure of sensitive internal information.
Technical details
A vulnerability in the Internal Operations component of Oracle Self-Service Human Resources (part of Oracle E-Business Suite) allows for unauthorized data access and manipulation. The flaw is exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read, insert, update, or delete a subset of data accessible to the Self-Service Human Resources module. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle addressed this issue in the July 2026 Critical Patch Update.
Affected products
- Oracle Corporation Self-Service Human Resources 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.