Impact
The vulnerability resides in the Oracle Unified Directory core component of Oracle Fusion Middleware and is caused by improper privilege management, identified as CWE‑269. A low‑privileged attacker who can reach the LDAP interface over the network can exploit the flaw, achieving full compromise of the directory service. Successful exploitation results in loss of confidentiality, integrity, and availability because the attacker can read, modify, or delete directory entries and gain administrative control.
Affected Systems
Affected versions include Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0. These are components of Oracle Fusion Middleware, and the vulnerability pertains to the OUD Core component.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 reflects high severity, with significant confidentiality, integrity, and availability impact. The EPSS score is less than 1%, indicating a low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via LDAP traffic from an external network and requires only low privileged credentials; no user interface is needed. If exploited, the attacker gains full control of the directory service.
OpenCVE Enrichment