Junglewise Threat Intelligence

CVE-2026-62507: Oracle Time and Labor integrity vulnerability in Internal Operations

CVE-2026-62507 · Severity: medium · CVSS 5.3 · Published 2026-07-21

Technologies: Oracle Time and Labor. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Time and Labor, a component of the Oracle E-Business Suite used by organizations to manage employee hours and workforce tasks. An attacker with basic user access could potentially modify, create, or delete critical business data within the system. While the attack is considered difficult to execute, successful exploitation could compromise the integrity of payroll or labor records.

Technical details

This vulnerability affects the Internal Operations component of Oracle Time and Labor within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an integrity-impacting flaw that allows a low-privileged attacker with network access via HTTP to perform unauthorized creation, deletion, or modification of data. The attack complexity is rated as high, suggesting that successful exploitation requires specific conditions or significant effort beyond simple network connectivity. The vulnerability does not impact confidentiality or availability. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.

Affected products

  • Oracle Time and Labor 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats