cbcvebase.

Oracle Human Resources Management System vulnerabilities

35 known vulnerabilities affecting oracle/human_resources_management_system.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM16LOW3

Vulnerabilities

Page 2 of 2
CVE-2026-62453P3MEDIUMCVSS 6.3≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62453 [MEDIUM] CWE-200 CVE-2026-62453: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unautho
nvd
CVE-2026-62524P3MEDIUMCVSS 6.3≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62524 [MEDIUM] CWE-200 CVE-2026-62524: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - Ge Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauth
nvd
CVE-2026-62559P3MEDIUMCVSS 6.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62559 [MEDIUM] CWE-200 CVE-2026-62559: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may s
nvd
CVE-2026-61120P3HIGHCVSS 7.0≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61120 [HIGH] CWE-269 CVE-2026-61120: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this
nvd
CVE-2026-60344P3MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60344 [MEDIUM] CWE-284 CVE-2026-60344: Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR P Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (France). Successful attacks of this vulnerability can result in u
nvd
CVE-2026-61260P3MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61260 [MEDIUM] CWE-284 CVE-2026-61260: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized upda
nvd
CVE-2026-61255P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61255 [MEDIUM] CWE-284 CVE-2026-61255: Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Ze Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand). Successful attacks of this vulnerability can
nvd
CVE-2026-61252P4MEDIUMCVSS 5.4≥ 12.2.13, ≤ 12.2.152026-07-21
CVE-2026-61252 [MEDIUM] CWE-284 CVE-2026-61252: Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kon Vulnerability in the Oracle HRMS (Hong Kong) product of Oracle E-Business Suite (component: Hong Kong Payroll). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Hong Kong). Successful attacks of this vulnerability can resu
nvd
CVE-2026-62465P4MEDIUMCVSS 6.6≥ 12.2.9, ≤ 12.2.152026-07-21
CVE-2026-62465 [MEDIUM] CWE-284 CVE-2026-62465: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this
nvd
CVE-2026-61254P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61254 [MEDIUM] CWE-601 CVE-2026-61254: Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (Republic of Korea). Successful attacks require human inte
nvd
CVE-2026-61253P4MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61253 [MEDIUM] CWE-352 CVE-2026-61253: Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Pa Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HRMS (Japanese). Successful attacks require human interaction
nvd
CVE-2026-61123P4MEDIUMCVSS 4.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61123 [MEDIUM] CWE-200 CVE-2026-61123: Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unaut
nvd
CVE-2026-61036P4LOWCVSS 3.8≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61036 [LOW] CWE-284 CVE-2026-61036: Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payr Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Norway Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). Successful attacks of this vulnerability can result in unauth
nvd
CVE-2026-61214P4LOWCVSS 2.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61214 [LOW] CWE-200 CVE-2026-61214: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in unauthorized read
nvd
CVE-2026-60950P4LOWCVSS 2.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60950 [LOW] CWE-200 CVE-2026-60950: Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal O Vulnerability in the Oracle HRMS (Ireland) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Ireland). Successful attacks of this vulnerability can result
nvd
Oracle Human Resources Management System vulnerabilities | cvebase