PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-62557 Oracle Corporation CVE debrief

A vulnerability was discovered in Oracle HRMS (UK), a product of Oracle E-Business Suite, specifically in the UK Payroll component. The affected versions are 12.2.3-12.2.15. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data, as well as unauthorized update, insert, or delete access to some of Oracle HRMS (UK) accessible data. The CVSS 3.1 Base Score is 7.1, indicating high severity with Confidentiality and Integrity impacts.

Vendor
Oracle Corporation
Product
Oracle HRMS (UK)
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Organizations using Oracle HRMS (UK) versions 12.2.3-12.2.15 should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing network access controls, ensuring that only authorized personnel have access to critical systems, and applying patches or updates as recommended by Oracle.

Technical summary

The vulnerability in Oracle HRMS (UK) is caused by inadequate security controls in the UK Payroll component. An attacker with low privileges and network access via HTTP can exploit this vulnerability. Successful exploitation can result in unauthorized access to critical data or complete access to all Oracle HRMS (UK) accessible data. Additionally, attackers may achieve unauthorized update, insert, or delete access to some Oracle HRMS (UK) accessible data. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N, reflecting a high severity score of 7.1 due to Confidentiality and Integrity impacts.

Defensive priority

High priority should be given to patching or mitigating this vulnerability in Oracle HRMS (UK) versions 12.2.3-12.2.15. Organizations should review their current configurations, ensure proper network access controls are in place, and apply patches or updates as recommended by Oracle. Monitoring for suspicious activity and maintaining up-to-date inventory of affected systems are also crucial.

Recommended defensive actions

  • Apply patches or updates recommended by Oracle for Oracle HRMS (UK) versions 12.2.3-12.2.15.
  • Review and enforce strict network access controls to limit access to critical systems.
  • Monitor for suspicious activity and maintain an up-to-date inventory of affected systems.
  • Ensure that only authorized personnel have access to critical systems and data.
  • Consider implementing compensating controls if patches cannot be applied immediately.

Evidence notes

The CVE record was published on 2026-07-21T22:19:08.763Z and was last modified on 2026-07-22T14:17:23.867Z. The NVD entry is currently 7.1 (Confidentiality and Integrity impacts). Evidence is limited to public sources and may not reflect the full scope or details of the vulnerability. Defenders should verify the affected versions (12.2.3-12.2.15) and configurations in their environments, review network access controls, and ensure that only authorized personnel have access to critical systems and data. Additional verification tasks may be necessary as more information becomes available.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:19:08.763Z and has not been modified since then.