Impact
The vulnerability is an access control weakness allowing unauthenticated LDAP traffic to fully compromise Oracle Unified Directory. An attacker receives the ability to read, modify, or delete directory data, and can disrupt or shut down the service, resulting in total loss of confidentiality, integrity, and availability for the component.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware, are affected.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 marks this flaw as critical; the EPSS score of < 1% indicates a low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated network access to the LDAP interface, which requires no credentials and therefore can be exploited by any host that can reach the directory server over the network.
OpenCVE Enrichment