Impact
A weakness in the Oracle Unified Directory OUD Core component permits a low‑privileged attacker that can reach the directory service via LDAP to create, delete, or modify critical entries. The flaw results in significant confidentiality and integrity loss, and because OUD is often used by downstream Oracle applications, the impact can propagate to those products. The vulnerability does not enable arbitrary code execution but grants the attacker full write access to directory data, effectively allowing the attacker to alter authentication information, group memberships, and other sensitive attributes.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are the only versions currently marked as affected. No other product versions or components have been listed as impacted.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.2 signals a high severity with substantial confidentiality and integrity impact. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not catalogued in the CISA KEV list. Exploitation requires network access to the LDAP interface and a low‑privileged account that can send crafted LDAP modify requests; upon success the attacker acquires comprehensive write authority over the directory and can thereby corrupt or expose data accessed by other Oracle products.
OpenCVE Enrichment