Impact
Oracle Unified Directory (OUD) Core suffers an easily exploitable vulnerability through LDAP that permits an attacker with low privilege and network access to create, delete, or modify data, thereby breaching confidentiality and integrity. Once breached, the attacker can gain unauthorized access to or alter critical data stored in the directory. The impact ranges from data manipulation to potential loss of critical information.
Affected Systems
Affected systems are Oracle Unified Directory version 14.1.2.1.0, part of Oracle Fusion Middleware. The vulnerability may also influence other products accessed through the directory due to the scope change noted in the advisory, increasing the risk to organizations that rely on OUD for authentication or access control.
Risk and Exploitability
The CVSS v3.1 score of 9.9 marks this as critical, with confidentiality, integrity, and availability damages. The EPSS score is below 1%, suggesting it is not widely exploited, and it is not listed in CISA’s KEV catalog. Nevertheless, the low attack complexity and requirement for low privilege coupled with network‑based LDAP access mean that a nearby attacker can easily exploit the flaw if LDAP services are reachable over the network. The risk profile remains high due to the severe potential data loss and unauthorized service disruption that could occur even with minimal privileges.
OpenCVE Enrichment