Vulnerability in Oracle E-Business Suite HRMS Product
CVE-2026-61117

6.3MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61117?

A vulnerability exists in the Oracle HRMS (UK) component of the Oracle E-Business Suite, affecting versions 12.2.8 through 12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to potentially compromise the HRMS product. While primarily affecting Oracle HRMS (UK), the impact of an attack could extend to other interconnected products, leading to unauthorized access and exposure of sensitive data. Proper security measures should be implemented to mitigate risk and protect against such threats.

Affected Version(s)

Oracle HRMS (UK) 12.2.8 <= 12.2.15

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.