Impact
The vulnerability is a privilege escalation flaw in Oracle Unified Directory that lets an attacker with high‑privilege LDAP credentials take full control of the directory service. This weakness is a CWE‑269 elevation of privilege error, and it results in complete compromise of confidentiality, integrity, and availability of the directory, potentially allowing further attacks on connected applications. Based on the description, it is inferred that the attacker exploits the LDAP protocol by performing privileged bind requests and then using those rights to modify or delete directory entries, effectively hijacking the system.
Affected Systems
Oracle Unified Directory in Oracle Fusion Middleware is affected. The specific releases impacted are version 12.2.1.4.0 and 14.1.2.1.0. No other vendors or product lines are listed in the advisory.
Risk and Exploitability
The CVSS 3.1 score of 7.2 indicates high severity, with serious confidentiality, integrity, and availability impacts. The EPSS score is less than 1%, implying a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. The likely attack vector is the LDAP network interface, and the exploitation requires an attacker to already possess or acquire high‑privilege LDAP credentials within the environment, limiting the threat scope to systems with such credentials exposed over the network.
OpenCVE Enrichment