Junglewise Threat Intelligence

CVE-2026-61117: Oracle HRMS (UK) confidentiality breach in Internal Operations

CVE-2026-61117 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (UK), a module within the Oracle E-Business Suite used for managing human resources and payroll. An attacker with basic user access could potentially gain unauthorized access to sensitive employee data or other critical information stored within the system. While the flaw is difficult to exploit, a successful attack could compromise the confidentiality of HR records and potentially impact other integrated Oracle products.

Technical details

This vulnerability affects the Internal Operations component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.8 through 12.2.15. It is classified as a confidentiality-impacting flaw that is difficult to exploit (High Attack Complexity). An attacker requires low-privileged credentials and network access via HTTP to execute the exploit. A successful attack results in a scope change (S:C), meaning the impact can extend beyond the HRMS (UK) component to other products or data within the E-Business Suite environment. The primary impact is the unauthorized access to or complete disclosure of sensitive data.

Affected products

  • Oracle HRMS (UK) (Oracle E-Business Suite) 12.2.8-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats