Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Netherlands Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Netherlands). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Netherlands). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Tue, 25 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oracle human Resources Management System
|
|
| CPEs | cpe:2.3:a:oracle:human_resources_management_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle human Resources Management System
|
Fri, 21 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High-Privilege Network Exploit Allows Full Takeover of Oracle HRMS Netherlands Payroll |
Thu, 20 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High-Privilege Network Exploit Allows Full Takeover of Oracle HRMS Netherlands Payroll | |
| Weaknesses | CWE-269 |
Thu, 20 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 CWE-284 |
Wed, 19 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High-Privilege Network Vulnerability in Oracle HRMS Netherlands Payroll | |
| Weaknesses | CWE-269 CWE-284 |
Wed, 19 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High-Privilege Network Vulnerability in Oracle HRMS Netherlands Payroll | |
| Weaknesses | CWE-269 CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Business Suite (component: Netherlands Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (Netherlands). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (Netherlands). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle hrms |
|
| CPEs | cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle hrms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:03:31.876Z
Updated: 2026-08-20T18:00:17.958Z
Reserved: 2026-08-04T22:06:34.617Z
Link: CVE-2026-71104
Updated: 2026-08-20T17:51:23.606Z
Status : Analyzed
Published: 2026-08-18T21:18:10.720
Modified: 2026-08-25T19:02:54.797
Link: CVE-2026-71104
No data.