CVE-2026-62521: High severity Oracle Oracle E-Business Suite vulnerability
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - US Payroll - General (Oracle HRMS (US))to a version that resolves this vulnerability.Fixed in 12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62521?
The severity of CVE-2026-62521 is classified as high with a score of 7.5.
How do I fix CVE-2026-62521?
To fix CVE-2026-62521, update to a non-vulnerable version of Oracle E-Business Suite, specifically versions 12.2.16 or later.
What are the potential impacts of CVE-2026-62521?
CVE-2026-62521 can allow an unauthenticated attacker to compromise Oracle HRMS (US) through HTTP access.
Which versions of Oracle E-Business Suite are affected by CVE-2026-62521?
The affected versions of Oracle E-Business Suite are 12.2.7 through 12.2.15.
Who can exploit CVE-2026-62521?
CVE-2026-62521 can be easily exploited by unauthenticated attackers with network access.