Junglewise Threat Intelligence

CVE-2026-62560: Oracle HRMS (Norway) information disclosure in Internal Operations

CVE-2026-62560 · Severity: high · CVSS 7.7 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Norway-specific Human Resources Management System (HRMS) component of Oracle E-Business Suite. This software is used by organizations to manage employee data, payroll, and internal operations. An attacker with basic user access could exploit this flaw to gain unauthorized access to sensitive corporate data, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the Internal Operations component of Oracle HRMS (Norway) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure flaw that is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is notable for a 'Scope Change' (S:C), indicating that a successful exploit can impact resources beyond the security scope of the HRMS component. Successful exploitation results in high confidentiality impacts, potentially allowing complete access to all data accessible by the HRMS module. The issue was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle HRMS (Norway) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References