Executive brief
Oracle HR Intelligence, a human resources management component of Oracle E-Business Suite, is affected by a vulnerability in its internal operations that allows low-privilege users with network access to corrupt or delete critical HR data. Successful exploitation can also force the system to hang or crash repeatedly, preventing legitimate users from accessing employee and payroll information.
Technical details
The vulnerability is a difficult-to-exploit integrity and availability flaw in Oracle HR Intelligence (versions 12.2.3–12.2.15) affecting internal operations, reachable via HTTP. An attacker with low privilege level and network access can exploit this issue without user interaction to modify, create, or delete critical HR data or cause a denial of service through repeated crashes or hangs. The CVSS 3.1 score of 6.8 reflects high integrity and availability impacts but no confidentiality loss. Patches or workarounds are expected from Oracle.
Affected products
- Oracle HR Intelligence 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed