Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (New Zealand) accessible data as well as unauthorized read access to a subset of Oracle HRMS (New Zealand) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification and Disclosure via Oracle HRMS HTTP Interface
Weaknesses CWE-200
CWE-284

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Enables Unauthorized HR Data Modification in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-640

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Enables Unauthorized HR Data Modification in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-640

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Access in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privilege HTTP Access in Oracle HRMS (New Zealand)
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (New Zealand) product of Oracle E-Business Suite (component: New Zealand Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (New Zealand). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (New Zealand) accessible data as well as unauthorized read access to a subset of Oracle HRMS (New Zealand) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2026-07-21T21:38:56.429Z

Updated: 2026-07-22T15:29:02.044Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61255

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.