Impact
An attacker with local access to the infrastructure on which Oracle Payroll runs can exploit a vulnerability that leads to full compromise of the Payroll application. The flaw enables an attacker to gain control of the system, resulting in loss of confidentiality, integrity, and availability of payroll data. The effect extends beyond the Payroll application, potentially affecting other components of the Oracle E‑Business Suite.
Affected Systems
Affected versions are Oracle Payroll 12.2.3 through 12.2.15. Oracle Corporation’s Payroll component within the Oracle E‑Business Suite is the product impacted.
Risk and Exploitability
The vulnerability has a CVSS v3.1 score of 8.8, reflecting high severity with local attack, low access complexity, and low privileges required. The EPSS score is < 1% and the flaw is not listed in the CISA KEV catalog. The attack requires only a low‑privileged local account with access to the infrastructure where Oracle Payroll is installed, making it relatively easy for an insider or anyone with physical or network access to the environment to exploit. Given the high CVSS score and the ease of exploitation, the risk remains significant.
OpenCVE Enrichment