Executive brief
A vulnerability exists in the Oracle HCM Configuration Workbench, a tool used within the Oracle E-Business Suite for managing human resources data. An attacker could remotely access the system to view, modify, or delete sensitive HR information without needing a username or password. This could lead to data breaches, unauthorized changes to employee records, or temporary disruptions to the service.
Technical details
This vulnerability affects the Spreadsheet Loading component of Oracle HCM Configuration Workbench within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is categorized as an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation enables the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of accessible data and can result in a partial denial of service (DoS). The vulnerability has a CVSS 3.1 base score of 7.3, reflecting impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.
Affected products
- Oracle HCM Configuration Workbench 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published