CVE-2026-62548: High severity Oracle Oracle E-Business Suite (Oracle HRMS (US)) vulnerability
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62548?
The severity of CVE-2026-62548 is rated high with a score of 7.2.
What is the risk associated with CVE-2026-62548?
CVE-2026-62548 has a risk rating of 66, indicating a significant vulnerability.
How can I fix CVE-2026-62548?
To fix CVE-2026-62548, ensure your Oracle HRMS (US) is upgraded to a supported version beyond 12.2.15.
Who is affected by CVE-2026-62548?
CVE-2026-62548 affects supported versions of Oracle E-Business Suite specifically versions 12.2.3 through 12.2.15.
What type of access is required to exploit CVE-2026-62548?
CVE-2026-62548 can be exploited by a high privileged attacker with network access via HTTP.