Executive brief
Oracle E-Business Suite includes a Field Service module used to manage service operations and customer data. A vulnerability in this component allows low-privileged users with network access to read sensitive or complete operational data without authorization. This could expose critical customer information or service records stored in the system.
Technical details
This is an authorization bypass or information disclosure vulnerability in the Internal Operations component of Oracle Field Service. The vulnerability requires low privilege network access via HTTP and no user interaction, but affects only confidentiality (no integrity or availability impact). Attackers can read unauthorized data accessible through the Field Service application. Oracle has confirmed the vulnerability affects versions 12.2.3 through 12.2.15; patch status and specific root cause details are not available from the reference sources provided.
Affected products
- Oracle E-Business Suite Field Service 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed