Executive brief
Oracle HRMS (India) is a human resources management system component of Oracle E-Business Suite used by organizations to manage employee data and payroll operations. An authenticated attacker with network access can exploit a vulnerability in this module to read, modify, or delete sensitive employee and HR data without proper authorization, potentially affecting payroll, benefits, and personnel records.
Technical details
This vulnerability in Oracle E-Business Suite's HRMS (India) component allows a low-privileged authenticated attacker with network access via HTTP to bypass authorization controls. The attack requires valid credentials but no user interaction. Successful exploitation enables unauthorized creation, deletion, or modification of critical HR data, as well as unauthorized read access to all accessible data within the HRMS module. The vulnerability is easily exploitable and affects HRMS versions 12.2.3 through 12.2.15. Patch availability and specific technical remediation details are not provided in the advisory summary.
Affected products
- Oracle E-Business Suite HRMS (India) 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed