Impact
The vulnerability resides in the Oracle Payroll component of Oracle E-Business Suite. It allows a low‑privileged attacker with network access over HTTP to compromise the Payroll application, potentially taking full control of the system. The flaw is difficult to exploit but, if successful, results in a complete takeover with all confidentiality, integrity and availability properties compromised. The description and CVSS vector imply that improper access control or authorization checks are the root cause, roughly mapping to CWE-284.
Affected Systems
Affected systems are Oracle Corporation's Oracle Payroll, specifically the Internal Operations component. Supported versions 12.2.3 through 12.2.15 are impacted. No other versions or product variants are listed in the current advisory.
Risk and Exploitability
The CVSS base score of 7.5 designates a high severity vulnerability. The EPSS score indicates a very low exploitation probability (<1%), and the issue is not listed in the CISA KEV catalog. Because the flaw can be triggered by an actor with limited privileges and remote network access, the risk is significant for organizations that expose Oracle Payroll to external networks. While the low EPSS suggests that widespread exploitation is unlikely at present, the potential for a complete takeover warrants prompt remediation.
OpenCVE Enrichment