Impact
An Oracle Payroll vulnerability permits a low‑privileged attacker who can reach the system over HTTP to gain unauthorized access to critical payroll data. The flaw allows the attacker to read all information accessible through Oracle Payroll, potentially exposing sensitive employee and financial records. The weakness results from improper access control where the application fails to enforce sufficient checks before allowing data retrieval.
Affected Systems
Oracle Corporation’s Oracle Payroll product, versions 12.2.3 through 12.2.15, is affected. Users running these releases are vulnerable to the described exploitation.
Risk and Exploitability
The CVSS 3.1 score of 7.7 reflects a high impact on confidentiality with low complexity and privilege requirements. The attack vector is network‑based via HTTP, and the scope is altered, meaning the flaw could affect additional Oracle products. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is currently not listed in CISA’s KEV catalog, but the high score and the existence of a measurable exploit probability suggest substantial potential for misuse if the flaw is publicly known.
OpenCVE Enrichment