Description
Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (Republic of Korea). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Republic of Korea) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Republic of Korea) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Korean Payroll component of Oracle HRMS (Republic of Korea) permits an unauthenticated attacker who can reach the system over HTTP to perform unauthorized update, insert, delete, and read operations on a subset of the data. The vulnerability leads to confidentiality and integrity impact and requires the attacker to rely on a person other than themselves to initiate the action, indicating that direct remote exploitation is not possible without user interaction.

Affected Systems

Oracle Corporation’s Oracle HRMS (Republic of Korea) product, part of the Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. These versions include the Korean Payroll component which is the locus of the weakness.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 labels the threat as moderate, and the EPSS score of less than 1% indicates a very low likelihood of exploitation based on current data. The vulnerability is not listed in the CISA KEV catalog. Attackers must gain unauthenticated network access via HTTP and complete a user‑ted interaction to trigger the data‑manipulation or data‑exposure actions, limiting the ease of exploitation but still allowing significant integrity and confidentiality harm.

Generated by OpenCVE AI on August 4, 2026 at 01:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for HRMS (Republic of Korea) that addresses the Korean Payroll component and fixes the identified open redirect flaw (CWE-601) as released in the July 2026 security alert.
  • Validate all HTTP redirect URLs within HRMS, restricting them to a whitelist of approved destinations to eliminate open redirect risk (CWE-601).
  • Restrict HTTP access to the HRMS instance by whitelisting trusted IP ranges or enforcing VPN access so that only authorized personnel can reach the web interface.
  • Enable and monitor database auditing for write and read operations on HRMS data to detect unauthorized activity promptly.

Generated by OpenCVE AI on August 4, 2026 at 01:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Open Redirect Vulnerability Exposes Oracle HRMS (Republic of Korea) Data

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Open Redirect Vulnerability Exposes Oracle HRMS (Republic of Korea) Data

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Manipulation in Oracle HRMS Korean Payroll

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Manipulation in Oracle HRMS Korean Payroll

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite (component: Korean Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HRMS (Republic of Korea). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HRMS (Republic of Korea) accessible data as well as unauthorized read access to a subset of Oracle HRMS (Republic of Korea) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:16:32.422Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61254

cve-icon Vulnrichment

Updated: 2026-07-22T18:16:29.436Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')