Impact
A flaw in Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 – an Access Control weakness (CWE‑284) – allows a low‑privileged attacker with LDAP network access to compromise the directory. Successful exploitation gives the attacker unauthorized read, insert, update, or delete access to the directory’s data, effectively providing full control over the contents.
Affected Systems
The affected product is Oracle Unified Directory, versions 12.2.1.4.0 and 14.1.2.1.0.
Risk and Exploitability
The CVSS 3.1 base score of 8.5 indicates a high severity, and the EPSS score of < 1% suggests a low but not zero probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers can leverage the flaw over the network via LDAP, requiring only low‑privileged access. The impact includes confidentiality and integrity violations and could affect other Oracle Fusion Middleware products due to a scope change.
OpenCVE Enrichment