Impact
An attacker with network connectivity to the LDAP service can take full control of the directory server without any authentication. The vulnerability is significant, as it can lead to complete compromise impacting confidentiality, integrity, and availability of the data stored by the directory. The CVSS 3.1 base score of 8.1 indicates that the vulnerability is severe and carries high potential for damage.
Affected Systems
Affected systems are the Oracle Unified Directory component of Oracle Fusion Middleware in the 12.2.1.4.0 and 14.1.2.1.0 releases. These versions are referenced by the CPE strings provided and correspond to the standard product naming structure used by Oracle.
Risk and Exploitability
The risk of exploitation is moderated by the low EPSS score of less than 1%, and the vulnerability has not been reported in the CISA KEV catalog. Nonetheless, the attack vector is straightforward: an unauthenticated network attacker can send a crafted LDAP request to the directory server and gain administrative control. No special privileges or credentials are required, which makes broad exploitation plausible in environments with permissive LDAP access.
OpenCVE Enrichment