Impact
A flaw in the Internal Operations component of the Oracle Public Sector Payroll application permits an attacker who has only low privileges and network access via HTTP to fully compromise the system. The exploit leads to complete takeover, providing the attacker with full confidentiality, integrity, and availability violations, as the baseline CVSS calculation indicates high impact to all three core sub‑nets.
Affected Systems
The vulnerability affects Oracle Public Sector Payroll from version 12.2.3 through 12.2.15. These releases are part of Oracle’s E‑Business Suite and are used by public sector payroll administrations.
Risk and Exploitability
Because the attack can be launched from any network location with HTTP connectivity, the entry vector is remote. The CVSS base score of 8.8 yields a severe rating, yet the EPSS score of less than 1 % signals a very low current exploitation probability. Oracle does not list this issue in the CISA KEV catalog, so no documented exploit is available at present. Nonetheless, the potential for full system compromise mandates immediate attention.
OpenCVE Enrichment