Junglewise Threat Intelligence

CVE-2026-62453: Oracle HRMS (UK) data manipulation in Internal Operations

CVE-2026-62453 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (UK), a human resources management system within the Oracle E-Business Suite. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive HR data. Additionally, an exploit could disrupt business operations by causing a partial service outage.

Technical details

A vulnerability in the Internal Operations component of Oracle HRMS (UK) (part of Oracle E-Business Suite) allows for unauthorized data manipulation and disclosure. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to perform unauthorized update, insert, or delete operations on a subset of accessible data, as well as read sensitive information. It also allows for a partial denial of service (DoS) attack. The vulnerability affects versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle HRMS (UK) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats