Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
Fri, 21 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | HTTP Exploit Enables Unauthorized Payroll Data Access in Oracle Payroll |
Fri, 21 Aug 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privilege HTTP Exploit Enables Unauthorized Payroll Data Access | |
| Weaknesses | CWE-200 |
Thu, 20 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privilege HTTP Exploit Enables Unauthorized Payroll Data Access | |
| Weaknesses | CWE-200 CWE-284 |
Wed, 19 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Access via HTTP in Oracle Payroll (Versions 12.2.3‑12.2.15) | |
| Weaknesses | CWE-200 CWE-284 |
Wed, 19 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Access via HTTP in Oracle Payroll (Versions 12.2.3‑12.2.15) | |
| Weaknesses | CWE-200 CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle payroll |
|
| CPEs | cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle payroll |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-08-20T17:20:22.538Z
Reserved: 2026-08-04T22:06:34.607Z
Link: CVE-2026-70945
Updated: 2026-08-20T16:03:40.665Z
Status : Awaiting Analysis
Published: 2026-08-18T21:17:52.697
Modified: 2026-08-20T18:16:37.300
Link: CVE-2026-70945
No data.
OpenCVE Enrichment
Updated: 2026-08-21T06:00:11Z