Impact
The vulnerability exists in the internal operations component of Oracle E‑Business Tax. A user who can log on to the underlying infrastructure but does not have privileged application rights can create, delete or modify tax data that is critical to business operations and can also force the application to crash, resulting in a denial‑of‑service condition. The weakness is an improper access control and improper privilege management flaw.
Affected Systems
Oracle E‑Business Tax versions 12.2.3 through 12.2.15 are affected. The flaw is limited to the internal operations functionality of this product; no other Oracle products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates high integrity and availability impact. The attack vector is local, as implied by the CVSS vector AV:L, so a malicious actor only needs infrastructure log‑on credentials. Because the EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, it may not yet be widely exploited, but environments where infrastructure users have broad access remain at significant risk.
OpenCVE Enrichment