Executive brief
A vulnerability exists in the Internal Operations component of Oracle HRMS (US), a module within the Oracle E-Business Suite used for managing human resources and payroll data. A low-privileged user with access to the underlying system can exploit this flaw to cause the application to crash or hang, resulting in a denial of service. Additionally, an attacker could gain unauthorized access to view, modify, or delete sensitive personnel records, potentially disrupting business operations and compromising employee data privacy.
Technical details
This vulnerability affects the Internal Operations component of Oracle HRMS (US) within Oracle E-Business Suite versions 12.2.9 through 12.2.15. It is classified as a local exploit, requiring the attacker to have logon credentials to the infrastructure where the application executes. Successful exploitation allows a low-privileged user to cause a complete denial of service (hang or repeatable crash) and provides unauthorized read, update, insert, or delete access to a subset of the application's data. The vulnerability is described by Oracle as easily exploitable once local access is obtained. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle E-Business Suite (Oracle HRMS US) 12.2.9-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD