Impact
The vulnerability allows a low‑privileged attacker that can reach Oracle Payroll over HTTP to gain unauthorized access to sensitive data, potentially compromising all payroll data accessible through the affected system. The weakness is an access‑control flaw that fails to enforce adequate authorization, as indicated by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N. This flaw exposes high confidentiality impact but does not affect integrity or availability directly.
Affected Systems
Affected products are Oracle Corporation’s Oracle Payroll component of Oracle E‑Business Suite, specifically the Internal Operations module. Versions 12.2.3 through 12.2.15 are listed as vulnerable. The scope change noted in the advisory suggests that exploitation could potentially impact additional Oracle products beyond Payroll.
Risk and Exploitability
The CVSS base score of 7.7 denotes a high‑severity confidentiality impact, but the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been observed in large‑scale attacks. The likely attack vector is network‑based via HTTP, and successful exploitation requires only low privileges on the network. Despite the low exploitation likelihood, the potential for broad data exposure warrants timely remediation.
OpenCVE Enrichment