Executive brief
A vulnerability exists in the Data Removal Tool component of Oracle Human Resources, a module within the Oracle E-Business Suite used by organizations to manage employee data and compliance. A high-privileged user can exploit this flaw over the network to gain full control over the Human Resources system. This could lead to the unauthorized access, modification, or deletion of sensitive personnel records and a total loss of service availability.
Technical details
This vulnerability affects the Data Removal Tool component of Oracle Human Resources within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a high-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can result in a complete takeover of the Oracle Human Resources product, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.3 through 12.2.15. While the specific CWE is not provided in the advisory, the impact is described as a full system compromise. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Human Resources (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published