Vulnerability in Oracle HRMS (US) of Oracle E-Business Suite
CVE-2026-62465

6.6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62465?

This vulnerability affects the Oracle HRMS (US) component of the Oracle E-Business Suite, allowing low-privileged attackers with access to the execution environment to exploit the system. The vulnerability can lead to unauthorized data modification and the potential to cause significant downtime through Denial of Service (DoS) attacks. Attackers may gain the ability to read sensitive data and perform unauthorized operations including insert, update, or delete actions on the Oracle HRMS (US). Organizations using versions 12.2.9 through 12.2.15 are advised to implement appropriate security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Oracle HRMS (US) 12.2.9 <= 12.2.15

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.