Description
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Payroll accessible data as well as unauthorized read access to a subset of Oracle Payroll accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payroll. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Payroll component of Oracle E‑Business Suite is vulnerable to a low‑privileged attacker with network access via HTTP. Successful exploitation allows the attacker to create, modify, or delete payroll records, read privileged data, and trigger a partial denial of service. The problem is rooted in improper privilege checks and information exposure, classified under CWE‑200, CWE‑269, and CWE‑284.

Affected Systems

Oracle Payroll, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The flaw exists in the Payroll component accessed over HTTP.

Risk and Exploitability

The CVSS 3.1 base score of 6.3 indicates moderate severity for confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests that exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based via HTTP, requiring only low privilege access to the server. Although the exploitation probability is low, the potential impact on data security warrants prompt mitigation.

Generated by OpenCVE AI on August 4, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle Payroll patch disclosed in the July 2026 CPU advisory
  • Restrict web access to the Oracle Payroll endpoints to trusted IP ranges or enforce HTTPS
  • Implement least‑privilege access controls for all Payroll users and audit permissions regularly

Generated by OpenCVE AI on August 4, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Oracle Payroll Unauthorized Data Manipulation via Unrestricted HTTP Access

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Oracle Payroll Unauthorized Data Manipulation via Unrestricted HTTP Access

Mon, 27 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Oracle Payroll Unauthorized Access and Partial Denial of Service via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Payroll Unauthorized Access and Partial Denial of Service via HTTP

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-269
CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Payroll accessible data as well as unauthorized read access to a subset of Oracle Payroll accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payroll. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle payroll
CPEs cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payroll
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:32:35.286Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61216

cve-icon Vulnrichment

Updated: 2026-07-22T18:31:58.729Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control