Description
Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HRMS (Japanese). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Japanese) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Japanese) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in the Oracle HRMS (Japanese) component of Oracle E‑Business Suite permits unauthenticated modification, insertion, deletion, or retrieval of HRMS data over HTTPS. This vulnerability is an authorization bypass and access control weakness. The CVSS 3.1 Base Score of 5.4 indicates moderate impacts to confidentiality and integrity. An attacker can exploit the weakness by prompting a human user to trigger the vulnerable request, resulting in unauthorized access or alteration of sensitive employee information.

Affected Systems

Oracle HRMS (Japanese) within Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The affected module is Oracle Payroll Japanese.

Risk and Exploitability

The attack vector is external, over HTTPS, with no authentication required and low technical barrier, though it relies on a social‑engineering element where a user must invoke the vulnerable request. EPSS indicates a very low probability of widespread exploitation (<1%), but the CVSS severity demonstrates that a successful attack can compromise data integrity and confidentiality. The vulnerability is not listed in CISA’s KEV catalog, implying no widely publicized exploits yet.

Generated by OpenCVE AI on August 5, 2026 at 01:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to an unlisted version.
  • Restrict HTTPS access to Oracle HRMS (Japanese) to trusted IP ranges or enforce VPN usage.
  • Enable comprehensive auditing of HRMS data modification and access events to detect anomalous activity.
  • Educate users about the social‑engineering component of the attack to reduce the likelihood of successful exploitation.

Generated by OpenCVE AI on August 5, 2026 at 01:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Leading to Data Modification in Oracle HRMS Japanese
Weaknesses CWE-200
CWE-284
CWE-285

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification and Disclosure in Oracle HRMS (Japanese) Payroll Module
Weaknesses CWE-284
CWE-285

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification and Disclosure in Oracle HRMS (Japanese) Payroll Module
Weaknesses CWE-284
CWE-285

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Exposure via Oracle HRMS (Japanese) HTTPS
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Exposure via Oracle HRMS (Japanese) HTTPS
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (Japanese) product of Oracle E-Business Suite (component: Oracle Payroll Japanese). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HRMS (Japanese). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Japanese) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Japanese) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:16:43.976Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61253

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-285

    Improper Authorization