Impact
Oracle E‑Business Tax includes an improperly enforced access control that permits a low‑privileged network attacker to issue HTTP requests to internal operation endpoints. Once accessed, the attacker can create, delete or modify critical records and may read all data exposed by the product. This flaw directly leads to confidentiality and integrity violations and is classified as CWE‑284.
Affected Systems
Version 12.2.3 through 12.2.15 of Oracle E‑Business Tax in the Oracle E‑Business Suite are affected. The vulnerability is reachable over the public network via standard HTTP and does not require elevated privileges or special authentication.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity due to complete confidentiality and integrity impact. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers can leverage the missing authorization checks by sending crafted HTTP requests, meaning the condition for exploitation is network access to the service and a user with low‑privilege credentials.
OpenCVE Enrichment