Executive brief
A vulnerability exists in the Internal Operations component of Oracle Public Sector Payroll, a module within the Oracle E-Business Suite used for managing government and public sector employee compensation. A high-privileged attacker could exploit this flaw to gain full control over the payroll system. This could lead to the unauthorized disclosure of sensitive employee data, disruption of payroll operations, or fraudulent modification of financial records.
Technical details
This vulnerability affects the Internal Operations component of Oracle Public Sector Payroll (versions 12.2.4 through 12.2.15). It is classified as easily exploitable, requiring network access via HTTP. While the attack requires high privileges (PR:H), a successful exploit allows for a complete compromise of the product, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). The root cause is located within the Oracle E-Business Suite framework's handling of internal operations. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Public Sector Payroll (Oracle E-Business Suite) 12.2.4 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial advisory publication by Oracle
- 2026-07-21: advisory: NVD record created