Executive brief
A vulnerability exists in Oracle E-Business Tax, a component of the Oracle E-Business Suite used for managing corporate tax compliance and reporting. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive financial and tax data. This could lead to significant data integrity issues, unauthorized disclosure of financial records, and disruption of tax operations.
Technical details
This vulnerability affects the Internal Operations component of Oracle E-Business Tax within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. Successful exploitation allows an attacker to gain unauthorized creation, deletion, or modification access to critical data, as well as full read access to all data accessible by the E-Business Tax module. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Affected versions range from 12.2.3 through 12.2.15.
Affected products
- Oracle E-Business Tax 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update July 2026