Vulnerability in Oracle HRMS (UK) Payroll Product by Oracle
CVE-2026-62557

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62557?

This vulnerability in the Oracle HRMS (UK) Payroll component of Oracle E-Business Suite allows low privileged attackers to exploit network access via HTTP. A successful attack could lead to unauthorized access to confidential data, potentially compromising all accessible information within Oracle HRMS (UK). Attackers could perform unauthorized actions such as updates, inserts, or deletions on sensitive data. Organizations using supported versions between 12.2.3 and 12.2.15 must address this vulnerability to protect their critical data against exploitation.

Affected Version(s)

Oracle HRMS (UK) 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.