Impact
A flaw in the Internal Operations component of Oracle Payroll permits an attacker with low-level network access via HTTP to forge requests that create, delete, or alter payroll data. Based on the description, it is inferred that the vulnerability stems from insufficient verification of user privileges, enabling a low-privilege attacker to impact confidentiality and integrity of all payroll records.
Affected Systems
Oracle Corporation’s Oracle Payroll product is affected for all supported releases from 12.2.3 through 12.2.15. The issue can be reached over HTTP by anyone who can connect to the affected server and does not require elevated local or system privileges.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 classifies this vulnerability as high severity. Based on the description, it is inferred that the attacker only needs network connectivity and the ability to assume a low‑privilege role, implying a significant risk of successful compromise. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can use the HTTP interface to send crafted requests that bypass normal authorization checks and affect all payroll data accessible through Payroll.
OpenCVE Enrichment