Impact
An unpatched version of Oracle Unified Directory allows an unauthenticated attacker with ordinary network access who can communicate via LDAP to create, delete, modify or read directory data. This vulnerability also permits the attacker to cause a partial denial of service. The flaw exhibits characteristics of improper access control and can compromise confidentiality, integrity, and availability as reflected in a CVSS 3.1 Base Score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L).
Affected Systems
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware, are affected. These are available from Oracle Corporation and require no special configuration to be vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests that exploitation frequency is currently low but not negligible. The vulnerability is not listed in CISA KEV, yet it remains a significant risk because an attacker can exploit it without authentication by simply contacting the LDAP service on the network. If exploited, the attacker can gain unauthorized control over directory entries, steal or modify critical data, and disrupt directory services for legitimate users.
OpenCVE Enrichment