Oracle ERP Flaw Reaches HR Data

A KEV-listed Oracle E-Business Suite flaw is no longer just an ERP patch item. It can put HR systems and the personal data they hold into the breach path, which turns application compromise into privacy, notification, and fraud exposure. Estée Lauder says attackers exploited CVE-2025-61882 in Oracle E-Business Suite for HR operations, and it is notifying customers after the incident. The affected stack includes Oracle E-Business Suite and Oracle Concurrent Processing / BI Publisher Integration, which is the kind of business system that can concentrate employee and customer records in one place. The risk does not stop at the application server once those records are exposed. Any organization using ERP or HR platforms for personal data has to treat those systems as high-value targets, because compromise there can trigger downstream identity abuse and breach-notification obligations.

Part of the PlainSec briefing for 2026-07-22

Sources