Impact
The vulnerability in Oracle Payroll allows a low‑privileged attacker who can reach the system over HTTP to compromise the application. The flaw permits retrieval of all payroll data accessible to the victim, giving the attacker unauthorized read access to critical financial information. The weakness involves improper access control, as indicated by the CVSS vector that shows a low attack cost and a high confidentiality impact.
Affected Systems
Oracle Corporation's Oracle Payroll, part of the Oracle E‑Business Suite, is impacted. Versions 12.2.3 through 12.2.15 are known to be vulnerable. No other products are directly listed as affected, although exploitation may impact connected components due to a scope change.
Risk and Exploitability
The CVSS score of 7.7 signals a medium‑to‑high severity. The EPSS of less than 1 % means current known exploitation is rare, and the vulnerability is not in the CISA KEV catalog. However, the topology of the attack – remote over HTTP with low privileges – makes it attractive for targeted adversaries, especially for gaining sensitive payroll data.
OpenCVE Enrichment