Vulnerability in Oracle HRMS (US) Product of Oracle E-Business Suite
CVE-2026-62559

6.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62559?

A vulnerability has been identified in the Oracle HRMS (US) product that allows an attacker with high privileges and network access via HTTP to exploit the system. This issue affects multiple supported versions, specifically from 12.2.3 to 12.2.15, potentially compromising sensitive data within the Oracle HRMS (US) application. The ramifications of successful exploitation could lead to unauthorized access to critical databases, raising significant security concerns across interconnected systems.

Affected Version(s)

Oracle HRMS (US) 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.