Executive brief
A vulnerability exists in the Internal Operations component of Oracle HRMS, a human resources management system used by organizations to manage employee data and payroll. A low-privileged user with existing access to the underlying server infrastructure could exploit this flaw to take full control of the HRMS application. This could lead to the unauthorized disclosure of sensitive personnel records, manipulation of payroll data, or a complete disruption of HR services.
Technical details
A vulnerability in the Internal Operations component of Oracle HRMS (US) within Oracle E-Business Suite allows for a complete compromise of the application. The flaw affects versions 12.2.3 through 12.2.15. Exploitation requires a low-privileged attacker to have local logon access to the infrastructure where the HRMS software executes. While the vulnerability is classified as difficult to exploit (High Attack Complexity), a successful attack results in a total loss of confidentiality, integrity, and availability for the affected component. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle Corporation E-Business Suite (Oracle HRMS US) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory