Description
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability exists in Oracle Payroll component of Oracle E‑Business Suite. The flaw lets an attacker with only low privileges and a network connection over HTTP reach the application in a way that bypasses authentication. The attacker can then read or modify employee payroll data, giving them access to highly confidential information, or gain complete access to all Payroll data. The weakness is a flaw in access control (CWE‑284).

Affected Systems

Affected are Oracle Payroll versions 12.2.3 through 12.2.15 inclusive. These are part of Oracle E‑Business Suite and are reachable over standard HTTP ports. The vulnerability is relevant only to those deployments that expose the Payroll service to a network that an attacker can reach.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity with high confidentiality impact; the low EPSS score suggests that exploitation is presently unlikely. The flaw is not listed in CISA’s KEV catalog. Attacks would require an attacker to have network connectivity to the Payroll application, likely over HTTP on the public or internal network, and only low but non‑zero privilege to exploit the access‑control weakness.

Generated by OpenCVE AI on August 4, 2026 at 01:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Payroll to a version newer than 12.2.15 or apply the latest security patch issued by Oracle for this component.
  • Restrict HTTP access to the Payroll application to a limited set of trusted IP addresses or a VPN.
  • Enforce strict role‑based access controls so that only authorized personnel can view or modify payroll data, and log all access attempts for audit purposes.

Generated by OpenCVE AI on August 4, 2026 at 01:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Oracle Payroll Leading to Unauthorized Data Exposure

Thu, 30 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Oracle Payroll Leading to Unauthorized Data Exposure

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged Network Access Compromise in Oracle Payroll

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low-Privileged Network Access Compromise in Oracle Payroll

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle payroll
CPEs cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payroll
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:19:17.599Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61250

cve-icon Vulnrichment

Updated: 2026-07-22T19:19:14.040Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses