Vulnerability in Oracle E-Business Suite Norway Payroll Component
CVE-2026-60892

6.6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60892?

A vulnerability exists in the Oracle HRMS (Norway) component of the Oracle E-Business Suite, specifically in versions 12.2.8 through 12.2.15. This issue enables attackers with high privileges and remote network access to exploit this vulnerability, significantly risking the integrity and confidentiality of the system. Successful exploitation can lead to full control over the Oracle HRMS (Norway) environment, allowing malicious actors to manipulate payroll data and access sensitive information. Organizations utilizing affected versions are urged to apply recommended patches and follow security best practices to mitigate potential threats.

Affected Version(s)

Oracle HRMS (Norway) 12.2.8 <= 12.2.15

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.