Vulnerability in Oracle E-Business Suite HRMS by Oracle
CVE-2026-61123

4.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-61123?

A security vulnerability exists in Oracle HRMS, a component of Oracle E-Business Suite, that can be exploited by attackers with limited privileges who can access the network via HTTP. This weakness can lead to unauthorized reading of sensitive data and may allow attackers to initiate a partial denial of service, thereby disrupting the operation of Oracle HRMS. It affects various versions from 12.2.3 to 12.2.15. Organizations using Oracle HRMS should take immediate steps to secure their systems against this vulnerability.

Affected Version(s)

Oracle HRMS (US) 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.