Executive brief
A vulnerability exists in the Internal Operations component of Oracle HRMS (US), a module within the Oracle E-Business Suite used for managing human resources and payroll data. An attacker with high-level administrative privileges could exploit this flaw over the network to gain full control of the HRMS system. This could lead to the unauthorized access, modification, or deletion of sensitive employee records and payroll information, potentially disrupting business operations and compromising data privacy.
Technical details
A vulnerability in the Internal Operations component of Oracle HRMS (US) within Oracle E-Business Suite versions 12.2.3 through 12.2.15 allows for a complete system compromise. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation results in a total loss of confidentiality, integrity, and availability (takeover) of the Oracle HRMS (US) instance. While the specific vulnerability class (e.g., injection, insecure deserialization) is not explicitly named in the advisory, the impact is categorized as a full system compromise. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle E-Business Suite (Oracle HRMS US) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-62548 by Oracle and NVD.