Executive brief
A vulnerability exists in the Appraisals component of Oracle Performance Management, a tool used by organizations to manage employee evaluations and performance data. An attacker with basic user credentials can remotely access the system to view, modify, or delete sensitive performance records. This could lead to unauthorized changes in employee appraisals and the exposure of private personnel information.
Technical details
This vulnerability affects the Appraisals component of Oracle Performance Management within the Oracle E-Business Suite. It is classified as an improper access control or data validation issue that allows a low-privileged attacker with network access via HTTP to compromise the system. An exploit can lead to unauthorized 'update, insert, or delete' access to some data, as well as unauthorized read access to a subset of accessible data. The attack does not require user interaction and has a low complexity. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Performance Management 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed