Impact
Oracle Field Service allows a low‑privileged network attacker to perform unauthorized data operations—creation, deletion, or modification—via HTTP requests, as well as potentially cause a partial denial of service. This flaw arises from missing or improper access controls (CWE‑284) and unchecked permissions before sensitive actions, leading to large confidentiality and integrity impacts (CVSS 3.1 Base Score 7.1). The flaw resides in the Internal Operations component of Oracle E‑Business Suite and permits these actions without requiring user authentication, but does require network access to the HTTP interface. The available description does not explicitly state that authentication is required; it is inferred that an attacker does not need prior authentication to exploit this vulnerability.
Affected Systems
Oracle Field Service versions 12.2.3 through 12.2.15 are affected. The flaw exists within the Internal Operations component of Oracle E‑Business Suite. No other versions or components are listed as impacted.
Risk and Exploitability
The EPSS score is < 1 % and the issue is not listed in CISA KEV, yet the vulnerability remains high risk due to its confidentiality, integrity, and partial availability impacts; the CVSS base score is 7.1. An attacker only needs low privileges and direct network access to HTTP endpoints to exploit the flaw. The description does not explicitly state that authentication is required; it is inferred that no authentication or privileged escalation steps are needed.
OpenCVE Enrichment