CVE-2026-62559: Infoleak
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (US) accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62559?
The severity of CVE-2026-62559 is medium with a CVSS score of 6.8.
How do I fix CVE-2026-62559?
To fix CVE-2026-62559, apply the latest security patches provided by Oracle for the affected versions of Oracle E-Business Suite.
What versions are affected by CVE-2026-62559?
CVE-2026-62559 affects Oracle E-Business Suite versions 12.2.3 to 12.2.15.
Can CVE-2026-62559 be exploited remotely?
Yes, CVE-2026-62559 can be easily exploited by a high privileged attacker with network access via HTTP.
What type of vulnerability is CVE-2026-62559 classified as?
CVE-2026-62559 is classified as an infoleak vulnerability.