Executive brief
Oracle E-Business Suite Payroll is a core financial module used by enterprises to manage employee compensation and benefits. A privilege escalation vulnerability in the Payroll component allows a low-privileged user with local system access to gain complete control over the Payroll system and potentially compromise related financial and HR systems. Successful exploitation could lead to unauthorized changes to payroll data, employee compensation manipulation, and exposure of sensitive personnel information.
Technical details
This is a local privilege escalation vulnerability in the Oracle Payroll component (Internal Operations) of Oracle E-Business Suite. The vulnerability requires low-level authentication and local system access to the infrastructure where the Payroll module executes, with no additional user interaction needed. An attacker can exploit this flaw to gain complete control (confidentiality, integrity, and availability compromise) over the Payroll system. Due to the integrated nature of E-Business Suite, successful exploitation may impact additional connected modules and systems. The vulnerability affects versions 12.2.3 through 12.2.15; patching or upgrade is the recommended remediation.
Affected products
- Oracle E-Business Suite Payroll 12.2.3-12.2.15
Timeline
- 2026-08-18: disclosed