Executive brief
Oracle E-Business Tax, a component of the Oracle E-Business Suite used for managing global tax requirements, contains a security vulnerability in its Internal Operations component. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive tax data. This could result in the theft, deletion, or modification of critical financial records, potentially impacting regulatory compliance and business operations.
Technical details
This vulnerability exists in the Internal Operations component of Oracle E-Business Tax (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack does not require user interaction. Successful exploitation grants the attacker high-impact access to confidentiality and integrity, allowing for the unauthorized creation, deletion, or modification of all data accessible to the E-Business Tax product. Affected versions include 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle E-Business Tax 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details as part of the July 2026 Critical Patch Update.
- 2026-07-21: disclosed