cbcvebase.

Oracle Human Resources Management System vulnerabilities

35 known vulnerabilities affecting oracle/human_resources_management_system.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM16LOW3

Vulnerabilities

Page 1 of 2
CVE-2026-62549P2CRITICALCVSS 9.6≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62549 [CRITICAL] CWE-284 CVE-2026-62549: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significan
nvd
CVE-2026-61121P2HIGHCVSS 8.8≥ 12.2.8, ≤ 12.2.152026-07-21
CVE-2026-61121 [HIGH] CWE-269 CVE-2026-61121: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in takeover of Oracle
nvd
CVE-2026-61122P3HIGHCVSS 8.1≥ 12.2.9, ≤ 12.2.152026-07-21
CVE-2026-61122 [HIGH] CWE-284 CVE-2026-61122: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized creati
nvd
CVE-2026-60965P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60965 [HIGH] CWE-284 CVE-2026-60965: Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2026-62530P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62530 [HIGH] CWE-284 CVE-2026-62530: Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2026-62521P3HIGHCVSS 7.5≥ 12.2.7, ≤ 12.2.152026-07-21
CVE-2026-62521 [HIGH] CWE-284 CVE-2026-62521: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - Ge Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unautho
nvd
CVE-2026-62456P3HIGHCVSS 8.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62456 [HIGH] CWE-269 CVE-2026-62456: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may s
nvd
CVE-2026-62560P3HIGHCVSS 7.7≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62560 [HIGH] CWE-200 CVE-2026-62560: Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Op Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). While the vulnerability is in Oracle HRMS (Norway), atta
nvd
CVE-2026-62567P3HIGHCVSS 7.7≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62567 [HIGH] CWE-200 CVE-2026-62567: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly
nvd
CVE-2021-2316P3HIGHCVSS 8.1≥ 12.1.1, ≤ 12.1.32021-04-22
CVE-2021-2316 [HIGH] CVE-2021-2316: Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in unauthorized creation,
nvd
CVE-2026-62548P3HIGHCVSS 7.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62548 [HIGH] CWE-269 CVE-2026-62548: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover
nvd
CVE-2026-62561P3HIGHCVSS 7.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62561 [HIGH] CWE-269 CVE-2026-62561: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this v
nvd
CVE-2026-62557P3HIGHCVSS 7.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62557 [HIGH] CWE-284 CVE-2026-62557: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized access
nvd
CVE-2026-62565P3HIGHCVSS 7.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62565 [HIGH] CWE-200 CVE-2026-62565: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2026-61119P3HIGHCVSS 7.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61119 [HIGH] CWE-284 CVE-2026-61119: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized creati
nvd
CVE-2026-61251P3MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61251 [MEDIUM] CWE-200 CVE-2026-61251: Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (component: Payroll). Supp Vulnerability in the HRMS (Australia) product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise HRMS (Australia). Successful attacks of this vulnerability can result in unauthorized access
nvd
CVE-2026-62556P3MEDIUMCVSS 6.5≥ 12.2.6, ≤ 12.2.152026-07-21
CVE-2026-62556 [MEDIUM] CWE-200 CVE-2026-62556: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unautho
nvd
CVE-2026-62562P3MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62562 [MEDIUM] CWE-284 CVE-2026-62562: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unautho
nvd
CVE-2026-61117P3MEDIUMCVSS 6.3≥ 12.2.8, ≤ 12.2.152026-07-21
CVE-2026-61117 [MEDIUM] CWE-200 CVE-2026-61117: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may
nvd
CVE-2026-60892P3MEDIUMCVSS 6.6≥ 12.2.8, ≤ 12.2.152026-07-21
CVE-2026-60892 [MEDIUM] CWE-284 CVE-2026-60892: Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payr Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.8-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this vulnerability can result in t
nvd
Oracle Human Resources Management System vulnerabilities | cvebase