Impact
A flaw exists in the Oracle Unified Directory product of Oracle Fusion Middleware, specifically the OUD Core component, which permits an attacker to connect via LDAP without authentication and exploit the system. Successful exploitation results in full compromise of the Oracle Unified Directory, yielding complete confidentiality, integrity, and availability loss, and can affect other components due to a scope change. The weakness is reflected in a CVSS 3.1 vector with a base score of 10.0, illustrating an extremely severe vulnerability that is easily exploitable and requires no privileged access.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. No other products are listed as impacted, but the scope change indicates that additional Oracle Fusion Middleware components could be impacted if the directory is compromised.
Risk and Exploitability
The CVSS score of 10.0 indicates maximum severity, and the EPSS score of < 1% shows that exploitation is considered low probability at this time, though not impossible. The vulnerability is listed as not in CISA KEV, so no known widespread exploitation is documented yet. The likely attack vector is a remote LDAP connection from an unauthenticated attacker, allowing direct takeover of the directory service.
OpenCVE Enrichment