Impact
The vulnerability resides in the Internal Operations component of Oracle Public Sector Payroll within Oracle E‑Business Suite. It permits an attacker with low level credentials and network access via HTTP to compromise the application, potentially gaining full control. The flaw allows an attacker to elevate privileges, modify access controls, and execute authentication bypass, leading to significant confidentiality, integrity and availability loss as reflected in the CVSS 3.1 Base Score of 8.8.
Affected Systems
Oracle Public Sector Payroll in versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite is affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk, yet the EPSS score of less than 1% and absence from the CISA KEV catalog suggest exploitation is currently rare. Inferred the attack vector is an unauthenticated or low‑privileged HTTP request that bypasses normal authentication. Successful exploitation would allow a user to take over or corrupt payroll data, impacting all users and potentially the organization’s financial operations.
OpenCVE Enrichment