Impact
The Oracle Payroll component of Oracle E‑Business Suite is vulnerable to a low‑privileged attacker with network access via HTTP. Successful exploitation allows the attacker to create, modify, or delete payroll records, read privileged data, and trigger a partial denial of service. The problem is rooted in improper privilege checks and information exposure, classified under CWE‑200, CWE‑269, and CWE‑284.
Affected Systems
Oracle Payroll, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The flaw exists in the Payroll component accessed over HTTP.
Risk and Exploitability
The CVSS 3.1 base score of 6.3 indicates moderate severity for confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests that exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based via HTTP, requiring only low privilege access to the server. Although the exploitation probability is low, the potential impact on data security warrants prompt mitigation.
OpenCVE Enrichment