Impact
The vulnerability stems from an improper access control mechanism in Oracle Payroll’s Internal Operations component. It allows an attacker with only low‑privileged local logon to the host where Oracle Payroll runs to obtain read access to all payroll data. The weakness is classified as CWE‑284. Because the scope is changed, exploitation may also affect other modules within Oracle E‑Business Suite.
Affected Systems
Affected are the Oracle Payroll product in Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15. The vulnerability resides in the Internal Operations component of the payroll module.
Risk and Exploitability
The CVSS base score is 6.5 with a local attack vector, low access complexity, low privileges, no user interaction, but a scope change. The EPSS score of <1% indicates that the likelihood of exploitation is low, and the vulnerability is not yet listed in CISA’s KEV. However, the potential impact on confidential payroll data, combined with the requirement of only local access, makes this vulnerability a moderate to high risk for organizations with incomplete isolation of payroll servers.
OpenCVE Enrichment