Impact
A remote HTTP vulnerability in Oracle Field Service allows an attacker with low privileges to acquire unauthorized access to critical data, potentially exposing all data accessible through the service. The weakness enables a breach of confidentiality while leaving integrity and availability unaffected, and is classified under CWE-284. The vulnerability requires only network access to the HTTP interface of the service to be exploited, making it relatively easy to engage for a low privileged attacker.
Affected Systems
Oracle Field Service, part of Oracle E‑Business Suite, is impacted. Supported affected releases range from 12.2.3 up to and including 12.2.15. No specific sub‑components or build details beyond the stated internal operations component are publicly disclosed, so any installation matching these versions is considered vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates moderate to high severity, focused mainly on confidentiality. The EPSS score being less than 1% suggests a very low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack vector is a network‑based HTTP interface and only requires low privileges, a determined attacker could repeatedly attempt to exploit the flaw once a foothold is established. The overall risk is moderate, but it warrants timely remediation.
OpenCVE Enrichment