Sceawere
Vulnerability Detail
CVE-2026-62549Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle HRMS UK Authorization Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle HRMS (UK)
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (UK) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-07-21T22:19:08.543Z",
"pubdate": "2026-07-21T22:19:08.543Z",
"executiveSummary": "This vulnerability exists within the UK Payroll component of the Oracle HRMS (UK) product suite, specifically impacting Oracle E-Business Suite versions 12.2.3 through 12.2.15.\nThe flaw allows a low-privileged, authenticated user to achieve unauthorized access to critical data and perform unauthorized modifications across the system.\nDue to the nature of the vulnerability, a successful exploit results in a significant scope change, potentially impacting the integrity and confidentiality of data beyond the immediate scope of the HRMS component.\nThe vulnerability is characterized by its ease of exploitation over standard HTTP network protocols, requiring minimal attacker capabilities.\nWith a CVSS 3.1 Base Score of 9.6, this vulnerability poses a critical risk to organizational data security, necessitating immediate attention to remediation efforts to prevent unauthorized data manipulation or exfiltration.",
"technicalDetails": "The vulnerability resides within the UK Payroll component of Oracle HRMS (UK). It functions as an authorization bypass that leverages a failure in server-side access control validation when processing HTTP requests.\nThe exploitation vector is entirely network-based (AV:N). An attacker with low-privileged network access can craft specific HTTP requests to the vulnerable component that bypasses internal checks intended to verify user permissions for sensitive operations.\nThe root cause appears to be an insufficient verification of user identity or scope permissions within the payroll processing logic, allowing an authenticated user to perform actions outside of their assigned security context.\nBecause this vulnerability supports a scope change (S:C), the impact is not limited to the local component. An attacker successfully exploiting this flaw can escape the sandbox of the HRMS application, potentially impacting other integrated products within the Oracle E-Business Suite environment.\nThe attack flow follows a structured path: 1) The attacker establishes a network connection to the targeted Oracle E-Business Suite instance via HTTP. 2) The attacker identifies a specific endpoint within the UK Payroll component that does not properly enforce role-based access control. 3) The attacker submits a malicious request designed to trigger an unauthorized creation, deletion, or modification of critical payroll data. 4) The server, failing to perform adequate authorization validation, processes the request as if it were legitimate, granting the attacker unauthorized access to sensitive datasets.\nThe post-exploitation impact includes full confidentiality and integrity breaches of HRMS data. An attacker can modify payroll records, delete historical data, or access sensitive employee information without triggering traditional access alerts. The ability to manipulate data structures indicates a lack of secondary validation within the database layer, allowing for significant downstream consequences.\nThe affected versions (12.2.3-12.2.15) indicate a persistent flaw in the authorization framework of the UK Payroll module that remained unpatched across multiple update cycles. Given the ease of exploitation (AC:L), no advanced technical knowledge or specialized social engineering is required to leverage this flaw once network connectivity is established."
}