CVE-2026-62560: Infoleak
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). While the vulnerability is in Oracle HRMS (Norway), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (Norway) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62560?
CVE-2026-62560 has a high severity rating of 7.7.
How do I fix CVE-2026-62560?
To fix CVE-2026-62560, apply the latest patches provided by Oracle for the affected versions of Oracle HRMS (Norway).
Who can exploit CVE-2026-62560?
CVE-2026-62560 can be exploited by a low privileged attacker with network access via HTTP.
What components of Oracle E-Business Suite are affected by CVE-2026-62560?
CVE-2026-62560 affects the Oracle HRMS (Norway) component of the Oracle E-Business Suite.
Which versions are impacted by CVE-2026-62560?
The impacted versions for CVE-2026-62560 are Oracle HRMS (Norway) versions 12.2.3 to 12.2.15.