Impact
A flaw in the Service Diagnostics Scripts component of Oracle Teleservice lets an unauthenticated attacker who can reach the service over HTTP update, insert, or delete accessible data, as well as read a subset of data. The weakness is improper access control (CWE‑284), resulting in unauthorized tampering with data integrity and potential leakage of confidential information.
Affected Systems
Oracle Teleservice within Oracle E‑Business Suite is impacted. Versions 12.2.3 to 12.215 are vulnerable per Oracle’s CPU July 2026 alert. Any deployment of these Teleservice versions that exposes the HTTP interface is at risk.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate severity with low confidentiality and integrity impact. The EPSS score is below 1%, reflecting a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated HTTP request to the Teleservice endpoint; no credentials are required, but the attacker must have network access to the service.
OpenCVE Enrichment