Executive brief
Oracle Field Service is a component of Oracle E-Business Suite that manages field operations and customer service workflows. A vulnerability in this component allows an attacker with network access to perform unauthorized modifications (create, update, or delete operations) and read sensitive data by tricking authenticated users into performing actions. The attack requires user interaction and can impact not only Field Service but other interconnected E-Business Suite systems.
Technical details
This is a cross-site request forgery (CSRF) or privilege-escalation vulnerability in the Oracle Field Service component of E-Business Suite (Internal Operations module). The vulnerability is easily exploitable and requires a low-privileged attacker with network access via HTTP. An attacker can exploit this by sending a malicious link or request to an authenticated user, who must interact with it to trigger the vulnerability. Successful exploitation results in unauthorized read access to sensitive data and unauthorized create/update/delete operations on Field Service records. The scope impact indicates that attacks against Field Service may cascade to compromise other E-Business Suite products. Patches are available from Oracle for affected versions 12.2.3 through 12.2.15.
Affected products
- Oracle E-Business Suite Field Service 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed