Impact
The vulnerability in Oracle Unified Directory allows a low‑privileged attacker with LDAP network access to compromise the directory server. Because the flaw gives the attacker control over the LDAP service, the attacker can gain full confidentiality, integrity, and availability of the directory. The weakness represents an improper access control that permits takeover of the Oracle Unified Directory instance, effectively resulting in full directory takeover and system compromise.
Affected Systems
Oracle Corporation’s Oracle Unified Directory component of Oracle Fusion Middleware is affected. Versions 12.2.1.4.0 and 14.1.2.1.0 are explicitly listed as vulnerable applications.
Risk and Exploitability
The CVSS v3.1 base score of 9.9 illustrates the extreme severity, and the EPSS score of less than 1 percent indicates a low probability of exploitation at present, yet the vulnerability is classified as easily exploitable with a network attack vector (LDAP). The flaw also changes scope, meaning that successful compromise may impact related components. Though not currently listed in CISA’s KEV catalog, the combination of high impact and low exploitation probability necessitates immediate attention. An attacker with limited local privileges can leverage the LDAP interface to elevate authority and eventually take over the entire directory service.
OpenCVE Enrichment