Executive brief
A vulnerability exists in Oracle Time and Labor, a component of the Oracle E-Business Suite used by organizations to manage employee hours and workforce data. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive records. This could result in the theft, deletion, or modification of critical payroll and labor data, potentially disrupting business operations and compromising employee privacy.
Technical details
This vulnerability affects the Internal Operations component of Oracle Time and Labor within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires only low-privileged authentication and can be triggered remotely via HTTP. An attacker can achieve high confidentiality and integrity impacts, allowing for the unauthorized viewing, creation, modification, or deletion of all data accessible to the Time and Labor module. The vulnerability does not impact system availability (A:N). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Time and Labor 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed: CVE-2026-62504 was published to the NVD.