Junglewise Threat Intelligence

CVE-2026-62505: Oracle E-Business Suite data manipulation in Time and Labor

CVE-2026-62505 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Technologies: Oracle Time and Labor. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Time and Labor, a component of the Oracle E-Business Suite used by organizations to manage employee hours and workforce data. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive labor-related information. This could lead to unauthorized changes in payroll data or the exposure of private employee records, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the Internal Operations component of Oracle Time and Labor within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a network-based attack that requires no prior authentication but does necessitate human interaction (User Interaction: Required) from a legitimate user. The CVSS vector indicates a 'Scope Change,' suggesting the vulnerability may be a Cross-Site Scripting (XSS) or similar injection flaw that allows an attacker to bypass security boundaries to impact other products. Exploitation can result in unauthorized read, update, insert, or delete access to a subset of the application's data. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite (Oracle Time and Labor) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats