PatchSiren cyber security CVE debrief
CVE-2026-62557 Oracle Corporation CVE debrief
A vulnerability was discovered in Oracle HRMS (UK), a product of Oracle E-Business Suite, specifically in the UK Payroll component. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data, as well as unauthorized update, insert, or delete access to some of Oracle HRMS (UK) accessible data. The CVSS 3.1 Base Score is 7.1, indicating high severity with Confidentiality and Integrity impacts.
- Vendor
- Oracle Corporation
- Product
- Oracle HRMS (UK)
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Organizations using Oracle HRMS (UK) versions 12.2.3-12.2.15 should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing network access controls, ensuring that only authorized personnel have access to critical systems, and applying patches or updates as recommended by Oracle.
Technical summary
The vulnerability in Oracle HRMS (UK) is caused by inadequate security controls in the UK Payroll component. An attacker with low privileges and network access via HTTP can exploit this vulnerability. Successful exploitation can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. Additionally, attackers may achieve unauthorized update, insert, or delete access to some Oracle HRMS (UK) accessible data. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N, reflecting a high severity score of 7.1 due to Confidentiality and Integrity impacts.
Defensive priority
High priority should be given to patching or mitigating this vulnerability in Oracle HRMS (UK) versions 12.2.3-12.2.15. Organizations should review their current configurations, ensure proper network access controls are in place, and apply patches or updates as recommended by Oracle. Monitoring for suspicious activity and maintaining up-to-date inventory of affected systems are also crucial.
Recommended defensive actions
- Apply patches or updates recommended by Oracle for Oracle HRMS (UK) versions 12.2.3-12.2.15.
- Review and enforce strict network access controls to limit access to critical systems.
- Monitor for suspicious activity and maintain an up-to-date inventory of affected systems.
- Ensure that only authorized personnel have access to critical systems and data.
- Consider implementing compensating controls if patches cannot be applied immediately.
Evidence notes
The CVE record was published on 2026-07-21T22:19:08.763Z and was last modified on 2026-07-22T14:17:23.867Z. The NVD entry is currently 7.1 (Confidentiality and Integrity impacts). Evidence is limited to public sources and may not reflect the full scope or details of the vulnerability. Defenders should verify the affected versions (12.2.3-12.2.15) and configurations in their environments, review network access controls, and ensure that only authorized personnel have access to critical systems and data. Additional verification tasks may be necessary as more information becomes available.
Official resources
-
CVE-2026-62557 CVE record
CVE.org
-
CVE-2026-62557 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:19:08.763Z and has not been modified since then.