Impact
The Oracle Payroll component of Oracle E‑Business Suite can be compromised by an attacker who has only low network privileges. An exploit that is easily triggered over HTTP allows the attacker to gain control of Payroll and potentially other internal operations. The flaw can lead to a full takeover, violating confidentiality, integrity, and availability, as reported by the CVSS 3.1 score of 8.8.
Affected Systems
Affected are Oracle Payroll releases from version 12.2.3 up through 12.2.15, part of the Oracle E‑Business Suite package. Only systems running these product editions are at risk; any newer releases beyond 12.2.15 are not affected.
Risk and Exploitability
Based on the description, the likely attack vector is via HTTP from external network connections with low privileges. The vulnerability’s CVSS base score of 8.8 signals high severity, but the EPSS score of less than 1 % indicates that real‑world exploitation is currently unlikely. It is not yet listed in the CISA Known Exploited Vulnerabilities catalog. The vulnerability is exploitable remotely over standard HTTP, requiring only low network privileges, so an attacker with network visibility could activate the flaw without additional authentication or insider knowledge.
OpenCVE Enrichment