Executive brief
A vulnerability exists in the Korean Payroll component of Oracle E-Business Suite, which manages human resources and payroll operations for organizations in South Korea. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive payroll and HR data. This could lead to unauthorized changes in employee records or the exposure of private financial information.
Technical details
A vulnerability in the Oracle HRMS (Republic of Korea) product of Oracle E-Business Suite, specifically within the Korean Payroll component, allows for unauthorized data access and modification. The flaw is exploitable by an unauthenticated attacker with network access via HTTP. Exploitation requires human interaction from a legitimate user (UI:R), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side injection. Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of accessible HRMS data. The vulnerability affects versions 12.2.3 through 12.2.15.
Affected products
- Oracle E-Business Suite (Oracle HRMS Republic of Korea) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published