CVE-2026-60924: High severity Oracle Oracle Public Sector Payroll vulnerability
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are within the affected scope?
Oracle Public Sector Payroll installations in Oracle E-Business Suite running supported versions 12.2.3 through 12.2.15 are affected. The affected component is Internal Operations.
What does an attacker need to exploit this issue?
An attacker needs network access to the target over HTTP and low-privileged access. No user interaction is required, and the attack complexity is low.
What is the likely impact of successful exploitation?
Successful exploitation can result in takeover of Oracle Public Sector Payroll. The reported impacts include high confidentiality, integrity, and availability impact.