Executive brief
Oracle Payroll, a critical financial and HR management system within Oracle E-Business Suite, contains an authentication or authorization vulnerability that allows low-privileged users to access sensitive payroll data. An authenticated attacker with network access can exploit this flaw to view confidential employee and payroll information, potentially affecting other connected enterprise modules due to shared infrastructure.
Technical details
A network-accessible vulnerability in Oracle Payroll (component: Internal Operations) allows a low-privileged authenticated attacker to bypass authorization controls and access restricted payroll data. The vulnerability has a low attack complexity and requires only valid user credentials and network access via HTTP; no user interaction is needed. Successful exploitation results in high-impact confidentiality breach with no integrity or availability impact, and the scope is changed (impacts systems beyond the Payroll application itself). Patches are available for versions 12.2.3 through 12.2.15.
Affected products
- Oracle E-Business Suite Payroll 12.2.3 through 12.2.15
Timeline
- 2026-08-18: disclosed