Junglewise Threat Intelligence

CVE-2026-61123: Oracle HRMS (US) information disclosure and partial DoS in Internal Operations

CVE-2026-61123 · Severity: medium · CVSS 4.2 · Published 2026-07-21

Technologies: Oracle HRMS (US). Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (US), a human resources management system within the Oracle E-Business Suite. An attacker with low-level user access could potentially view sensitive HR data or cause a partial disruption of the service. While the impact is limited to a subset of data and partial service availability, it could affect internal business operations and data privacy.

Technical details

This vulnerability affects the Internal Operations component of Oracle HRMS (US) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as difficult to exploit, requiring the attacker to have low-privileged credentials and network access via HTTP. Successful exploitation allows an attacker to gain unauthorized read access to a subset of HRMS data and cause a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle HRMS (US) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats