Impact
A vulnerability in Oracle Field Service allows a low privileged attacker with network access via HTTP to gain unauthorized access to critical data. The flaw is an insecure direct object reference (CWE-284), enabling the attacker to read, update, insert, or delete data, and also to trigger a partial denial of service. The impact affects confidentiality (high), integrity (low), and availability (low), which together raise the overall threat level.
Affected Systems
The affected product is Oracle Corporation: Oracle Field Service, specifically the Internal Operations component. Versions 12.2.3 through 12.2.15 are impacted. The flaw is reachable over standard HTTP connections exposed to the network.
Risk and Exploitability
The CVSS 3.1 score of 7.6 indicates a high severity vulnerability. The EPSS score is less than 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would typically target the HTTP interface, require only low privileges, and no user interaction. If exploited, the attacker could compromise a breadth of data and partially disrupt service availability.
OpenCVE Enrichment