Executive brief
A vulnerability exists in the Internal Operations component of Oracle Public Sector Payroll, a module within the Oracle E-Business Suite used for managing government and public sector employee compensation. A high-privileged attacker could exploit this flaw over the network to gain full control of the payroll system. This could lead to the unauthorized access of sensitive employee data, disruption of payroll operations, and loss of data integrity.
Technical details
This vulnerability affects the Internal Operations component of Oracle Public Sector Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a high-privileged attacker with network access via HTTP to compromise the application. Successful exploitation results in a complete takeover of the Oracle Public Sector Payroll module, impacting confidentiality, integrity, and availability. The attack requires high administrative privileges but no user interaction. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Public Sector Payroll (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD