Sceawere

Vulnerability Detail

CVE-2026-71104UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle HRMS Netherlands Payroll Takeover

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle HRMS (Netherlands)
Attack Type
Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Netherlands). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Netherlands).
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Netherlands Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Netherlands). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Netherlands). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-18T21:18:10.720Z",
  "pubdate": "2026-08-18T21:18:10.720Z",
  "executiveSummary": "An exploitable vulnerability exists within the Oracle HRMS (Netherlands) product of Oracle E-Business Suite, specifically localized to the Netherlands Payroll component. This security flaw allows a highly privileged adversary with network access via the HTTP protocol to successfully compromise the targeted application.\nSuccessful exploitation of this vulnerability results in a complete system takeover, yielding severe impacts across confidentiality, integrity, and availability. The assigned CVSS 3.1 Base Score is 7.2 with the vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).\nThe vulnerability affects supported product versions ranging from 12.2.3 to 12.2.15. The attack vector is network-based, characterized by low attack complexity, requiring no user interaction, but necessitating high privileges from the threat actor to execute the exploit successfully.",
  "technicalDetails": "The vulnerability resides in the Netherlands Payroll component of Oracle HRMS (Netherlands) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The root cause stems from improper input validation or insufficient authorization controls within the administrative interfaces or processing functions exposed by the application layer.\nExploitation of this vulnerability requires the attacker to possess high privileges within the application environment. However, the attack surface is exposed over the network via the HTTP protocol, allowing remote interaction with the vulnerable component without requiring any user interaction or complex tactical conditions due to the low attack complexity.\nThe attack flow proceeds as follows: First, the authenticated attacker with elevated privileges leverages network access to transmit crafted HTTP requests directly to the vulnerable Netherlands Payroll component endpoints. Second, the underlying application processes the request without adequate validation, logic enforcement, or proper access restriction checks. Third, the lack of robust input sanitization or authorization validation allows the payload to execute arbitrary administrative or system-level routines within the application context.\nPost-exploitation impact includes the total takeover of the Oracle HRMS (Netherlands) product instance. Because the vulnerability compromises confidentiality, integrity, and availability comprehensively, an adversary can manipulate sensitive payroll and human resources data, execute unauthorized system commands, alter system configurations, or deny service to legitimate users."
}
CVE-2026-71104: Oracle HRMS Netherlands Payroll Takeover (HIGH Severity, CVSS: 7.2) - Sceawere