Executive brief
A vulnerability exists in the US Payroll Year End component of Oracle HRMS, a module within the Oracle E-Business Suite used for managing human resources and payroll processing. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive payroll and employee data. This could lead to the exposure of confidential information or unauthorized modifications to payroll records, potentially impacting financial integrity and regulatory compliance.
Technical details
A vulnerability in Oracle HRMS (US), specifically within the US Payroll Year End component of Oracle E-Business Suite, allows for unauthorized data access and manipulation. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read critical data or gain complete access to all Oracle HRMS (US) accessible data, as well as perform unauthorized updates, inserts, or deletions of certain records. The vulnerability affects versions 12.2.3 through 12.2.15 and was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle HRMS (US) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.