Executive brief
A vulnerability exists in the Oracle Payroll component of the Oracle E-Business Suite, which is used by organizations to manage employee compensation and tax filings. An employee or other user with low-level access to the system could potentially view, modify, or delete sensitive payroll data. Additionally, an attacker could disrupt payroll operations, leading to a partial service outage.
Technical details
This vulnerability affects the Payroll component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and is accessible over the network via HTTP. An attacker can exploit this to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of Oracle Payroll data. Furthermore, the exploit can be used to cause a partial denial of service (DoS) affecting the availability of the payroll system. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Payroll 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published