Impact
The vulnerability is a flaw in Oracle Field Service’s Internal Operations component that permits improper access control (CWE‑284). A remote attacker who can reach the service over HTTP, without needing privileged credentials, can read sensitive data and perform unauthorized insert, update or delete operations. The impact on confidentiality is high and on integrity is moderate, with no effect on availability.
Affected Systems
Oracle Field Service, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The issue resides in the Operations component of the product.
Risk and Exploitability
The CVSS v3.1 score of 7.1 indicates a significant threat to confidentiality and a moderate risk to integrity. Attackers require only network access to an exposed HTTP endpoint and have no privilege escalation requirement. The EPSS score is below 1 % and the flaw is not listed in the CISA KEV catalog, suggesting a currently low probability of exploitation but indicating that passive exposure should be mitigated immediately because of the high potential damage.
OpenCVE Enrichment