Impact
This vulnerability, classified as a local privilege escalation (CWE-269), allows a low privileged user who can log on to the environment where Oracle E-Business Tax runs to compromise the application, potentially taking over all its functions. The impact includes complete loss of confidentiality, integrity and availability for the tax subsystem, as reflected in its CVSS 3.1 score of 7.8.
Affected Systems
Oracle E-Business Tax versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The vulnerability is scored as high severity (CVSS 7.8) but the EPSS score indicates a very low exploitation probability (<1%). It is not listed in CISA’s KEV catalog. Exploitation requires local access; a low‑privileged local account can exploit insufficient access controls to gain full control of the application. Once compromised, an attacker can modify or delete tax data, disrupt operations or misuse confidential information.
OpenCVE Enrichment