Impact
Oracle Payroll versions 12.2.3 through 12.2.15 contain a flaw in internal operations that allows an attacker with a low‑privilege account and network access via HTTP to compromise the application. The weakness permits the attacker to bypass standard privilege limits (CWE‑269), improper access control (CWE‑284), improper authentication (CWE‑287), and missing authentication for critical functions (CWE‑306). As a result, the attacker can gain full control over payroll processing, access confidential employee information, alter payroll data, and potentially disrupt service availability.
Affected Systems
Oracle Corporation’s Oracle Payroll product, part of Oracle E‑Business Suite, is affected in all supported releases from 12.2.3 to 12.2.15. Systems running any of these versions that are reachable over HTTP are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high severity for confidentiality, integrity, and availability. The EPSS score is less than 1 %, suggesting that exploitation is uncommon but still realistic. The vulnerability is not listed in the CISA KEV catalog, so no known widespread exploits are reported. Based on the description, the likely attack vector is network‑based HTTP access, requiring only a low‑privilege account on the network to begin the compromise.
OpenCVE Enrichment