Executive brief
Oracle HRMS (US) is a payroll and human resources management system used to process employee compensation and tax withholding. A local privilege escalation flaw allows an authenticated user with low system privileges to gain complete control over the application, potentially exposing or altering sensitive payroll and employee tax data.
Technical details
This is a privilege escalation vulnerability in the US Payroll Tax component of Oracle HRMS (US), part of Oracle E-Business Suite. The vulnerability is easily exploitable by a low-privileged attacker with local logon access to the infrastructure; no complex exploitation techniques or user interaction is required. Successful exploitation grants the attacker complete control (confidentiality, integrity, and availability impact) over the HRMS (US) application and its data. The affected versions are 12.2.3 through 12.2.15. Patch availability from Oracle is expected via their regular Critical Patch Update cycle.
Affected products
- Oracle E-Business Suite HRMS (US) 12.2.3 to 12.2.15
Timeline
- 2026-08-18: disclosed