Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Common Architecture accessible data as well as unauthorized update, insert or delete access to some of Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Mon, 24 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access to Oracle HCM Common Architecture Allows Unauthorized Data Access |
Mon, 24 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Allows Data Compromise in Oracle HCM Common Architecture | |
| Weaknesses | CWE-200 CWE-285 |
Mon, 24 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Access Allows Data Compromise in Oracle HCM Common Architecture | |
| Weaknesses | CWE-200 CWE-285 |
Fri, 21 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Access in Oracle HCM Common Architecture | |
| Weaknesses | CWE-284 CWE-287 |
Wed, 19 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Access in Oracle HCM Common Architecture | |
| Weaknesses | CWE-284 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Common Architecture accessible data as well as unauthorized update, insert or delete access to some of Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). | |
| First Time appeared |
Oracle
Oracle hcm Common Architecture |
|
| CPEs | cpe:2.3:a:oracle:hcm_common_architecture:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle hcm Common Architecture |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:01:27.814Z
Updated: 2026-08-24T14:23:49.862Z
Reserved: 2026-08-04T22:06:34.596Z
Link: CVE-2026-70773
Updated: 2026-08-24T13:30:26.741Z
Status : Analyzed
Published: 2026-08-18T21:17:30.173
Modified: 2026-09-03T16:15:07.217
Link: CVE-2026-70773
No data.