Executive brief
A vulnerability exists in the Hong Kong Payroll component of Oracle E-Business Suite, which is used by organizations to manage employee compensation and tax compliance. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive payroll data. This could lead to unauthorized changes in financial records or the exposure of private employee information.
Technical details
A vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite, specifically within the Hong Kong Payroll component, allows for unauthorized data manipulation and disclosure. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read, update, insert, or delete a subset of data accessible to the HRMS module. The vulnerability affects versions 12.2.13 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle E-Business Suite (Oracle HRMS Hong Kong) 12.2.13-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published