CVE-2026-62567: Infoleak
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62567?
The severity of CVE-2026-62567 is rated high with a score of 7.7.
How do I fix CVE-2026-62567?
To fix CVE-2026-62567, apply the latest security patches provided by Oracle for the affected versions of the Oracle E-Business Suite.
What are the affected versions of CVE-2026-62567?
The affected versions of CVE-2026-62567 are Oracle E-Business Suite versions 12.2.3 to 12.2.15.
Who can exploit CVE-2026-62567?
CVE-2026-62567 can be easily exploited by a low privileged attacker with network access via HTTP.
What product is impacted by CVE-2026-62567?
CVE-2026-62567 impacts the Oracle HRMS (UK) component of the Oracle E-Business Suite.