Security Flaw in Oracle E-Business Suite's Field Service Component
CVE-2017-10170
8.2HIGH
Summary
This vulnerability in the Oracle Field Service component of the Oracle E-Business Suite allows an unauthenticated attacker to exploit the service via an HTTP connection. Successful exploitation can lead to unauthorized access to sensitive data and manipulation capabilities, including the potential to insert, update, or delete information across various accessible datasets. Attackers may need human interaction from a third party, amplifying the risk of data breaches and unauthorized transactions within Oracle Field Service and potentially affecting related products.
Affected Version(s)
Field Service 12.1.1
Field Service 12.1.2
Field Service 12.1.3
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved