CVE-2026-34297
HIGHOracle HCM Common Architecture 12.2.3-12.2.15 - Info Disclosure
Title source: llmDescription
Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Scores
CVSS v3
7.5
EPSS
0.0005
EPSS Percentile
14.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (2)
oracle/hcm_common_architecture
12.2.3 - 12.2.15
Oracle Corporation/Oracle HCM Common Architecture
12.2.3 - 12.2.15
Published
Apr 21, 2026
Tracked Since
Apr 22, 2026