Executive brief
Oracle Teleservice is a support and service management component within Oracle E-Business Suite, a comprehensive business software platform. A privilege escalation vulnerability in the Service Request Form allows low-privileged users with network access to gain complete control over the Teleservice system, potentially compromising confidentiality, integrity, and availability of customer service data and operations.
Technical details
This is a privilege escalation vulnerability in the Oracle Teleservice Service Request Form component affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable and requires only low privilege network-accessible credentials and HTTP access, with no additional user interaction needed. A successful exploit enables an attacker to achieve complete compromise of the Teleservice system, including unauthorized access to confidential data, modification of service records, and denial of service. The attack vector is network-based over HTTP with low attack complexity; patches should be available through Oracle's standard security update channels.
Affected products
- Oracle E-Business Suite Teleservice 12.2.3 to 12.2.15
Timeline
- 2026-08-18: disclosed