CVE-2026-62505: Medium severity Oracle Oracle E-Business Suite - Oracle Time and Labor vulnerability
Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Time and Labor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Time and Labor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Time and Labor accessible data as well as unauthorized read access to a subset of Oracle Time and Labor accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle Time and Labor (Internal Operations)to a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62505?
CVE-2026-62505 has a medium severity score of 6.1.
What impact does CVE-2026-62505 have on Oracle E-Business Suite?
CVE-2026-62505 allows an unauthenticated attacker to compromise Oracle Time and Labor with network access via HTTP.
Which versions of Oracle E-Business Suite are affected by CVE-2026-62505?
CVE-2026-62505 affects supported versions 12.2.3 through 12.2.15 of Oracle E-Business Suite.
How do I fix CVE-2026-62505?
To address CVE-2026-62505, apply the latest security patches provided by Oracle for the affected versions.
Is CVE-2026-62505 easily exploitable?
Yes, CVE-2026-62505 is considered easily exploitable due to its requirements for network access and lack of authentication.