Impact
A flaw in the Korean Payroll component of Oracle HRMS (Republic of Korea) permits an unauthenticated attacker who can reach the system over HTTP to perform unauthorized update, insert, delete, and read operations on a subset of the data. The vulnerability leads to confidentiality and integrity impact and requires the attacker to rely on a person other than themselves to initiate the action, indicating that direct remote exploitation is not possible without user interaction.
Affected Systems
Oracle Corporation’s Oracle HRMS (Republic of Korea) product, part of the Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. These versions include the Korean Payroll component which is the locus of the weakness.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 labels the threat as moderate, and the EPSS score of less than 1% indicates a very low likelihood of exploitation based on current data. The vulnerability is not listed in the CISA KEV catalog. Attackers must gain unauthenticated network access via HTTP and complete a user‑ted interaction to trigger the data‑manipulation or data‑exposure actions, limiting the ease of exploitation but still allowing significant integrity and confidentiality harm.
OpenCVE Enrichment