Executive brief
A vulnerability exists in the US Payroll component of Oracle E-Business Suite, a platform used by organizations to manage human resources and financial operations. An unauthorized person could exploit this flaw over the network to gain access to sensitive payroll and employee data without needing a username or password. This could lead to a significant breach of confidential employee information and regulatory compliance issues.
Technical details
This vulnerability in Oracle HRMS (US) affects the US Payroll - General component of Oracle E-Business Suite. It is classified as an information disclosure flaw that can be exploited by an unauthenticated attacker via HTTP over the network. The exploit is described as 'easily exploitable,' requiring no special privileges or user interaction. Successful exploitation allows an attacker to gain unauthorized access to critical data or complete access to all data accessible by the Oracle HRMS (US) module. The issue affects supported versions 12.2.7 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle E-Business Suite (Oracle HRMS US) 12.2.7-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-62521 was published to the NVD.