Impact
Oracle E‑Business Tax is vulnerable to a low‑privileged attack that allows an attacker with network access over HTTP to perform unauthorized creation, deletion or modification of data; the impact encompasses confidentiality and integrity loss of critical data without affecting availability. The weakness is an access‑control flaw that bypasses proper authorization checks as indicated by the CVSS vector.
Affected Systems
Affected versions are Oracle E‑Business Tax 12.2.3 through 12.2.15, part of Oracle E‑Business Suite; no explicit sub‑component or further version granularity is provided.
Risk and Exploitability
The CVSS v3.1 base score is 8.1, indicating high severity. The EPSS score is less than 1 %, suggesting a very low probability of exploitation in the near future. The vulnerability is not listed in the CISA KEV catalog. An attacker requiring only low privileges and network access via HTTP can exploit the flaw, potentially gaining unrestricted access to critical data and the ability to modify or delete it.
OpenCVE Enrichment