CVE-2026-60972: High severity Oracle Oracle E-Business Tax (Oracle E-Business Suite - Internal Operations) vulnerability
Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60972?
The severity of CVE-2026-60972 is rated as high with a CVSS score of 8.1.
How do I fix CVE-2026-60972?
To fix CVE-2026-60972, you should apply the latest security patches provided by Oracle for the affected versions of Oracle E-Business Tax.
What systems are affected by CVE-2026-60972?
CVE-2026-60972 affects Oracle E-Business Tax versions 12.2.3 to 12.2.15.
What is the impact of CVE-2026-60972?
The impact of CVE-2026-60972 is that a low privileged attacker with network access can compromise Oracle E-Business Tax.
Is CVE-2026-60972 easily exploitable?
Yes, CVE-2026-60972 is classified as easily exploitable, requiring only low privileges and network access via HTTP.