Vulnerability in Oracle HRMS (UK) by Oracle E-Business Suite
CVE-2026-62456

8.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62456?

This vulnerability in the Oracle HRMS (UK) product of the Oracle E-Business Suite enables a low privileged attacker with network access via HTTPS to compromise the system. Although primarily affecting the Oracle HRMS (UK), the scope of this vulnerability could potentially impact other associated products as well. Successful exploitation may lead to unauthorized creation, deletion, or modification of critical data within the Oracle HRMS (UK), resulting in significant risks to data confidentiality and integrity.

Affected Version(s)

Oracle HRMS (UK) 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.