Oracle Human Resources Management System vulnerabilities
35 known vulnerabilities affecting oracle/human_resources_management_system.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM16LOW3
Vulnerabilities
Page 2 of 2
CVE-2026-62453P3MEDIUMCVSS 6.3≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62453 [MEDIUM] CWE-200 CVE-2026-62453: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operat
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unautho
nvd
CVE-2026-62524P3MEDIUMCVSS 6.3≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62524 [MEDIUM] CWE-200 CVE-2026-62524: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - Ge
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauth
nvd
CVE-2026-62559P3MEDIUMCVSS 6.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62559 [MEDIUM] CWE-200 CVE-2026-62559: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may s
nvd
CVE-2026-61120P3HIGHCVSS 7.0≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61120 [HIGH] CWE-269 CVE-2026-61120: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this
nvd
CVE-2026-60344P3MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60344 [MEDIUM] CWE-284 CVE-2026-60344: Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR P
Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in u
nvd
CVE-2026-61260P3MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61260 [MEDIUM] CWE-284 CVE-2026-61260: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized upda
nvd
CVE-2026-61255P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61255 [MEDIUM] CWE-284 CVE-2026-61255: Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Ze
Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand). Successful attacks of this vulnerability can
nvd
CVE-2026-61252P4MEDIUMCVSS 5.4≥ 12.2.13, ≤ 12.2.152026-07-21
CVE-2026-61252 [MEDIUM] CWE-284 CVE-2026-61252: Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kon
Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kong Payroll). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Hong Kong). Successful attacks of this vulnerability can resu
nvd
CVE-2026-62465P4MEDIUMCVSS 6.6≥ 12.2.9, ≤ 12.2.152026-07-21
CVE-2026-62465 [MEDIUM] CWE-284 CVE-2026-62465: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this
nvd
CVE-2026-61254P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61254 [MEDIUM] CWE-601 CVE-2026-61254: Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component:
Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (Republic of Korea). Successful attacks require human inte
nvd
CVE-2026-61253P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61253 [MEDIUM] CWE-352 CVE-2026-61253: Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Pa
Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HRMS (Japanese). Successful attacks require human interaction
nvd
CVE-2026-61123P4MEDIUMCVSS 4.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61123 [MEDIUM] CWE-200 CVE-2026-61123: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unaut
nvd
CVE-2026-61036P4LOWCVSS 3.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61036 [LOW] CWE-284 CVE-2026-61036: Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payr
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this vulnerability can result in unauth
nvd
CVE-2026-61214P4LOWCVSS 2.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61214 [LOW] CWE-200 CVE-2026-61214: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized read
nvd
CVE-2026-60950P4LOWCVSS 2.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60950 [LOW] CWE-200 CVE-2026-60950: Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal O
Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Ireland). Successful attacks of this vulnerability can result
nvd
← Previous2 / 2