Executive brief
A critical vulnerability exists in the UK Payroll component of Oracle HRMS, a system used by organizations to manage human resources and employee compensation. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive payroll and employee data. Because the vulnerability allows for a 'scope change,' an attack could potentially spread to impact other integrated business systems beyond the HR module.
Technical details
This vulnerability affects the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw is notable for a 'scope change' (Status: Changed in CVSS), meaning a successful exploit can impact components or products beyond the immediate UK Payroll module. Attackers can achieve full confidentiality and integrity compromise, allowing for the unauthorized creation, deletion, or modification of all data accessible to the HRMS (UK) product. A patch is expected to be available through the Oracle Critical Patch Update (CPU) program.
Affected products
- Oracle Corporation HRMS (UK) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle Corporation
- 2026-07-21: advisory: NVD publication of CVE-2026-62549