Executive brief
A vulnerability exists in the Manager Self-Service component of Oracle's human resources software, which is used by organizations to manage employee data and payroll. An attacker with basic user credentials could exploit this flaw to gain unauthorized access to sensitive personnel information. This could lead to a significant breach of employee privacy and the exposure of confidential corporate data.
Technical details
This vulnerability affects the Manager Self-Service component of Oracle Self-Service Human Resources (E-Business Suite). It is classified as an information disclosure flaw that can be exploited by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction and has a high impact on confidentiality, potentially allowing the attacker to access all data within the affected component. The vulnerability is present in versions 12.2.3 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Self-Service Human Resources (E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD