Executive brief
A vulnerability exists in the UK Payroll component of Oracle HRMS, a module within the Oracle E-Business Suite used for managing human resources and payroll operations. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive employee and financial data. This could lead to the exposure of critical payroll information or unauthorized modifications to records, potentially impacting financial integrity and regulatory compliance.
Technical details
A vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite, specifically within the UK Payroll component, allows for unauthorized data access and manipulation. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to achieve high confidentiality impact, gaining access to all accessible data within the module, and low integrity impact, allowing for unauthorized updates, insertions, or deletions of certain records. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle HRMS (UK) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory