Executive brief
A vulnerability exists in Oracle Time and Labor, a component of the Oracle E-Business Suite used by organizations to manage employee hours and workforce data. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive personnel records. This could result in the theft, deletion, or modification of critical business data, potentially disrupting payroll operations and compromising employee privacy.
Technical details
This vulnerability affects the Internal Operations component of Oracle Time and Labor within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of all data accessible to the Time and Labor product. The exploit results in high impacts to confidentiality and integrity, though it does not directly impact service availability. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Time and Labor 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed