Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Human Resources. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Mon, 24 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via HTTP in Oracle Public Sector Human Resources | |
| Weaknesses | CWE-284 |
Fri, 21 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Remote Code Execution Vulnerability in Oracle Public Sector Human Resources Regression Testing | |
| Weaknesses | CWE-200 CWE-285 |
Wed, 19 Aug 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High Privilege Remote Code Execution Vulnerability in Oracle Public Sector Human Resources Regression Testing | |
| Weaknesses | CWE-200 CWE-285 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Human Resources. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle public Sector Human Resources |
|
| CPEs | cpe:2.3:a:oracle:public_sector_human_resources:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle public Sector Human Resources |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:01:53.717Z
Updated: 2026-08-24T19:54:21.439Z
Reserved: 2026-08-04T22:06:34.598Z
Link: CVE-2026-70802
Updated: 2026-08-24T19:49:42.851Z
Status : Awaiting Analysis
Published: 2026-08-18T21:17:34.383
Modified: 2026-08-24T20:17:05.497
Link: CVE-2026-70802
No data.