Description
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of the Oracle Public Sector Payroll application permits an attacker who has only low privileges and network access via HTTP to fully compromise the system. The exploit leads to complete takeover, providing the attacker with full confidentiality, integrity, and availability violations, as the baseline CVSS calculation indicates high impact to all three core sub‑nets.

Affected Systems

The vulnerability affects Oracle Public Sector Payroll from version 12.2.3 through 12.2.15. These releases are part of Oracle’s E‑Business Suite and are used by public sector payroll administrations.

Risk and Exploitability

Because the attack can be launched from any network location with HTTP connectivity, the entry vector is remote. The CVSS base score of 8.8 yields a severe rating, yet the EPSS score of less than 1 % signals a very low current exploitation probability. Oracle does not list this issue in the CISA KEV catalog, so no documented exploit is available at present. Nonetheless, the potential for full system compromise mandates immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 02:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Public Sector Payroll to the latest patched release that addresses this issue.
  • Restrict HTTP access to the payroll application by applying network segmentation or firewall rules to limit connections to trusted hosts.
  • Review and harden application access controls, ensuring that users with low privileges cannot invoke internal operations functions.
  • Monitor audit logs for suspicious authentication attempts and configuration changes to detect unauthorized activity.

Generated by OpenCVE AI on August 4, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Enables Low‑Privilege Full Compromise of Oracle Public Sector Payroll

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low Privileged Network Attack Allows Full Compromise of Oracle Public Sector Payroll
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privileged Network Attack Allows Full Compromise of Oracle Public Sector Payroll
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle public Sector Payroll
CPEs cpe:2.3:a:oracle:public_sector_payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Payroll
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Public Sector Payroll
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:10:15.350Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60924

cve-icon Vulnrichment

Updated: 2026-07-24T17:10:10.355Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:27.470

Modified: 2026-07-24T18:18:06.507

Link: CVE-2026-60924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function