Impact
Vulnerability exists in Oracle Payroll component of Oracle E‑Business Suite. The flaw lets an attacker with only low privileges and a network connection over HTTP reach the application in a way that bypasses authentication. The attacker can then read or modify employee payroll data, giving them access to highly confidential information, or gain complete access to all Payroll data. The weakness is a flaw in access control (CWE‑284).
Affected Systems
Affected are Oracle Payroll versions 12.2.3 through 12.2.15 inclusive. These are part of Oracle E‑Business Suite and are reachable over standard HTTP ports. The vulnerability is relevant only to those deployments that expose the Payroll service to a network that an attacker can reach.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity with high confidentiality impact; the low EPSS score suggests that exploitation is presently unlikely. The flaw is not listed in CISA’s KEV catalog. Attacks would require an attacker to have network connectivity to the Payroll application, likely over HTTP on the public or internal network, and only low but non‑zero privilege to exploit the access‑control weakness.
OpenCVE Enrichment