Executive brief
A vulnerability exists in the Payroll component of Oracle's Human Resources Management System (HRMS) for Australia. This software is used by organizations to manage employee compensation and tax compliance. An attacker with basic user credentials could exploit this flaw over the network to gain unauthorized access to sensitive payroll and employee data, potentially leading to a significant breach of confidential information.
Technical details
This vulnerability affects the Payroll component of Oracle HRMS (Australia) within Oracle E-Business Suite. It is classified as an information disclosure flaw that is easily exploitable by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction and has a high impact on confidentiality, potentially allowing complete access to all HRMS (Australia) data accessible to the component. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation HRMS (Australia) (Payroll) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-61251 was published to the NVD.