Impact
A vulnerability exists in Oracle Unified Directory that allows an unauthenticated attacker with network access via LDAP to compromise the system. The flaw, while difficult to exploit, grants full takeover of the Oracle Unified Directory service. The CVSS base score is 9.0, indicating significant confidentiality, integrity, and availability impacts.
Affected Systems
Oracle Unified Directory, part of Oracle Fusion Middleware, is affected in versions 12.2.1.4.0 and 14.1.2.1.0. Because the vulnerability can change the scope of the compromise, additional Oracle products that rely on the directory could also be impacted.
Risk and Exploitability
The exploit requires network access to the LDAP interface and no authentication, yet it has a high complexity requirement. EPSS indicates a very low current probability of exploitation, but the lack of a KEV listing does not mitigate the potential for a future, high‑impact attack. The high CVSS score combined with scope change suggests a severe risk if the flaw is exploited.
OpenCVE Enrichment