Executive brief
A vulnerability exists in the Oracle Public Sector Payroll component of the Oracle E-Business Suite, which manages payroll operations for government and public sector organizations. A high-privileged attacker could exploit this flaw to gain full control over the payroll system. This could lead to the unauthorized disclosure of sensitive employee data, disruption of payroll processing, or manipulation of financial records.
Technical details
This vulnerability (CWE-284) affects the Internal Operations component of Oracle Public Sector Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is characterized as an improper access control issue that is easily exploitable by an attacker with high administrative privileges. Exploitation occurs over the network via HTTP without requiring user interaction. A successful attack results in a complete takeover of the affected product, impacting the confidentiality, integrity, and availability of the system. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.
Affected products
- Oracle Corporation Public Sector Payroll 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle Corporation
- 2026-06-17: advisory: NVD publication date