Executive brief
A vulnerability exists in the Install component of Oracle HCM Configuration Workbench, a tool used for managing Human Capital Management setups within the Oracle E-Business Suite. An attacker with low-level user credentials could remotely access the system to view, modify, or delete sensitive configuration data. Additionally, this flaw could be used to disrupt the availability of the workbench, potentially impacting administrative operations.
Technical details
This vulnerability affects the Install component of Oracle HCM Configuration Workbench within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. A successful exploit allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the workbench's data and can lead to a partial denial of service (DoS). The vulnerability has been addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle HCM Configuration Workbench (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed