Executive brief
Oracle Time and Labor, a component of the Oracle E-Business Suite used by organizations to manage employee hours and work schedules, contains a security vulnerability. A low-privileged user could exploit this flaw to cause a partial service outage, potentially disrupting time-tracking operations. While the impact is limited to availability, it could interfere with administrative tasks and payroll processing workflows.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Time and Labor (Oracle E-Business Suite). The flaw is accessible via HTTP over a network and requires low-privileged authentication. Although the attack complexity is rated as high, a successful exploit allows an attacker to impact the availability of the service, resulting in a partial denial of service (DoS). The vulnerability affects versions 12.2.3 through 12.2.15. No confidentiality or integrity impacts are reported. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle Time and Labor 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.