Impact
The vulnerability lies in the Internal Operations component of Oracle Field Service, allowing a low‑privileged attacker who can reach the application via HTTP to bypass authorization controls and access critical data. This failure of proper authorization permits an adversary to read or potentially exfiltrate all data managed by the product, delivering a high confidentiality impact without affecting integrity or availability.
Affected Systems
Oracle Field Service, part of Oracle E‑Business Suite, is vulnerable in versions 12.2.3-12.2.15. Instances of these releases that are reachable from an external network are at risk, and the scope change indicates that other Oracle products might also be impacted if the flaw is leveraged across the deployment.
Risk and Exploitability
With a CVSS 3.1 base score of 7.7, the flaw represents moderate to high risk, primarily for confidentiality. The EPSS score is below 1%, indicating a low probability of widespread exploitation, and it is not listed in CISA’s KEV catalog. The attacker must only have network access to the Oracle Field Service HTTP user account; once exposed, the vulnerability is considered easily exploitable without additional prerequisites.
OpenCVE Enrichment