CVE-2026-62561: High severity Oracle Oracle E-Business Suite (Internal Operations) - Oracle HRMS (US) vulnerability
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62561?
The severity of CVE-2026-62561 is rated high with a score of 7.8.
How do I fix CVE-2026-62561?
To fix CVE-2026-62561, you should apply the latest security updates provided by Oracle for the affected versions of Oracle E-Business Suite.
What versions of Oracle E-Business Suite are affected by CVE-2026-62561?
The affected versions of Oracle E-Business Suite are 12.2.3 through 12.2.15.
Who is vulnerable to CVE-2026-62561?
Low privileged attackers with logon access to the infrastructure where Oracle HRMS (US) executes are vulnerable to CVE-2026-62561.
What components of Oracle E-Business Suite does CVE-2026-62561 affect?
CVE-2026-62561 affects the Internal Operations component of the Oracle HRMS (US) product.