Description
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Immediately
AI Analysis

Impact

A remote HTTP vulnerability in Oracle Field Service allows an attacker with low privileges to acquire unauthorized access to critical data, potentially exposing all data accessible through the service. The weakness enables a breach of confidentiality while leaving integrity and availability unaffected, and is classified under CWE-284. The vulnerability requires only network access to the HTTP interface of the service to be exploited, making it relatively easy to engage for a low privileged attacker.

Affected Systems

Oracle Field Service, part of Oracle E‑Business Suite, is impacted. Supported affected releases range from 12.2.3 up to and including 12.2.15. No specific sub‑components or build details beyond the stated internal operations component are publicly disclosed, so any installation matching these versions is considered vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 6.5 indicates moderate to high severity, focused mainly on confidentiality. The EPSS score being less than 1% suggests a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack vector is a network‑based HTTP interface and only requires low privileges, a determined attacker could repeatedly attempt to exploit the flaw once a foothold is established. The overall risk is moderate, but it warrants timely remediation.

Generated by OpenCVE AI on September 20, 2026 at 09:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or upgrade to a version later than 12.2.15 that addresses the HTTP credential validation flaw.
  • Restrict external network access to the Oracle Field Service HTTP endpoint using firewall or network segmentation, limiting exposure to trusted IP ranges only.
  • Review and enforce strict role‑based access controls for all users and services interacting with Field Service to ensure no unnecessary low‑privilege accounts are present.

Generated by OpenCVE AI on September 20, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title HTTP Credential Validation Flaw in Oracle Field Service Allows Unauthorized Data Access
Weaknesses CWE-285

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title HTTP Credential Validation Flaw in Oracle Field Service Allows Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle field Service
CPEs cpe:2.3:a:oracle:field_service:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle field Service
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Field Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:18:05.649Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83140

cve-icon Vulnrichment

Updated: 2026-09-17T14:22:59.039Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:24.637

Modified: 2026-09-17T16:18:04.987

Link: CVE-2026-83140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:30:18Z

Weaknesses