Executive brief
Oracle Field Service, a component of Oracle E-Business Suite used to manage field operations and customer service, contains an authorization flaw allowing attackers with low-level network access to read sensitive business data. A successful exploit grants complete access to Field Service data without proper permission checks, potentially exposing customer information and operational details across multiple connected enterprise systems.
Technical details
The vulnerability is an authorization bypass in Oracle Field Service (Internal Operations component) affecting versions 12.2.3 through 12.2.15. An attacker with low privileges and network access via HTTP can exploit this flaw to gain unauthorized read access to sensitive data. The scope is marked as changed, indicating that while the vulnerability resides in Field Service, successful exploitation may compromise other connected Oracle E-Business Suite products. The flaw results in high confidentiality impact with no integrity or availability impact.
Affected products
- Oracle E-Business Suite Field Service 12.2.3–12.2.15
Timeline
- 2026-09-15: disclosed