Executive brief
A vulnerability exists in the Japanese Payroll component of Oracle E-Business Suite, which is used by organizations to manage employee compensation and tax compliance in Japan. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive payroll data. This could lead to unauthorized changes to financial records or the exposure of private employee information.
Technical details
This vulnerability affects the Oracle Payroll Japanese component within Oracle HRMS (Japanese) versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that can be triggered over the network via HTTPS without prior authentication. However, the attack requires human interaction from a person other than the attacker (User Interaction: Required), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar UI-based redirection issue. An attacker who successfully exploits this can gain unauthorized read, update, insert, or delete access to a subset of the data accessible to the Oracle HRMS (Japanese) product. The impact is limited to confidentiality and integrity, with no reported impact on system availability.
Affected products
- Oracle HRMS (Japanese) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date