Impact
The flaw in the Oracle HRMS (Japanese) component of Oracle E‑Business Suite permits unauthenticated modification, insertion, deletion, or retrieval of HRMS data over HTTPS. This vulnerability is an authorization bypass and access control weakness. The CVSS 3.1 Base Score of 5.4 indicates moderate impacts to confidentiality and integrity. An attacker can exploit the weakness by prompting a human user to trigger the vulnerable request, resulting in unauthorized access or alteration of sensitive employee information.
Affected Systems
Oracle HRMS (Japanese) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The affected module is Oracle Payroll Japanese.
Risk and Exploitability
The attack vector is external, over HTTPS, with no authentication required and low technical barrier, though it relies on a social‑engineering element where a user must invoke the vulnerable request. EPSS indicates a very low probability of widespread exploitation (<1%), but the CVSS severity demonstrates that a successful attack can compromise data integrity and confidentiality. The vulnerability is not listed in CISA’s KEV catalog, implying no widely publicized exploits yet.
OpenCVE Enrichment