Impact
The affected product, Oracle Unified Directory, contains a flaw that permits an unauthenticated attacker with network access via HTTP to gain read access to all data managed by the directory service. This flaw results from missing authentication checks, reflecting CWE-306 (Missing Authentication). The vulnerability is characterized by a CVSS 3.1 base score of 8.6, with the impact confined primarily to confidentiality while integrity and availability remain unchanged.
Affected Systems
Oracle Corporation’s Oracle Unified Directory is affected in the 12.2.1.4.0 and 14.1.2.1.0 releases. These versions are part of Oracle Fusion Middleware and are the only publicly documented affected builds.
Risk and Exploitability
The CVSS vector indicates that the attack is achievable over the network (AV:N), requires no prior authentication (PR:N) and needs no user interaction (UI:N). The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalogue, but its high confidentiality impact and the fact that it does not require privileged access make it a notable risk for organizations exposing the directory over HTTP.
OpenCVE Enrichment