Description
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-60925 is a high‑privilege takeover vulnerability that allows an attacker who already possesses high‑privileged network access via HTTP to compromise the Oracle Public Sector Payroll application. The flaw is identified as CWE‑269, CWE‑284, and CWE‑306, and the description states it is easily exploitable. Based on the description, it is inferred that the attacker can bypass authentication controls and achieve full control of the payroll application, resulting in loss of confidentiality, integrity, and availability.

Affected Systems

Affected are Oracle Public Sector Payroll versions 12.2.4 through 12.2.15, part of the Oracle E‑Business Suite's Internal Operations component.

Risk and Exploitability

The CVSS 3.1 base score of 7.2 indicates moderate to high severity. EPSS score of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access over HTTP and may use the flaw to take complete control of the system. Based on the description, exploitation requires high‑privileged network access.

Generated by OpenCVE AI on August 5, 2026 at 01:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Oracle E‑Business Suite patch that addresses the Public Sector Payroll vulnerability, ensuring it is newer than version 12.2.15.
  • Restrict HTTP traffic to the payroll application to trusted internal hosts only and enforce strong authentication controls.
  • Disable or restrict any default or unused privileged accounts and enforce strict least‑privilege principles.
  • Enable detailed audit logging for privileged operations and monitor for suspicious access patterns.

Generated by OpenCVE AI on August 5, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via HTTP in Oracle Public Sector Payroll

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via HTTP in Oracle Public Sector Payroll

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via HTTP in Oracle Public Sector Payroll
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle public Sector Payroll
CPEs cpe:2.3:a:oracle:public_sector_payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Payroll
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Public Sector Payroll
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:59:35.806Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60925

cve-icon Vulnrichment

Updated: 2026-07-24T16:59:29.995Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:27.577

Modified: 2026-07-24T18:18:06.630

Link: CVE-2026-60925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function