Impact
A flaw in Oracle Field Service’s Internal Operations component permits an attacker with low privileges to submit requests over HTTP that can update, insert, or delete data, or read restricted information. The vulnerability is exploitable only when a user other than the attacker interacts with the interface, indicating that the attacker must capture the victim’s credentials or otherwise convince the victim to perform the operation. Because the bug lives in Oracle Field Service, the impact can extend to other Oracle products that share the same data or infrastructure, raising the overall scope of the attack.
Affected Systems
The flaw affects Oracle Corporation’s Oracle Field Service, versions 12.2.3 through 12.2.15. The affected component is Internal Operations, which interfaces with the HTTP protocol to process transaction data.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 reflects confidentiality and integrity impacts with no availability change. The EPSS score of <1% indicates the likelihood of real‑world exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires network access to the HTTP endpoint, low privileges, and a second user to perform a trusted action, which limits widespread exploitation but still constitutes a moderate risk to data integrity and confidentiality for environments where privileged users are targeted.
OpenCVE Enrichment