Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote, unauthenticated attacker with network access to the LDAP interface of Oracle Unified Directory can trigger an easily exploitable flaw that causes the server to hang or repeatedly crash. The vulnerability does not expose data or permit remote code execution; it only impacts availability, as reflected in its CVSS base score of 7.5.

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware’s OUD Core component, are affected.

Risk and Exploitability

The EPSS score indicates a very low but non‑zero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a simple LDAP request over the network to an exposed LDAP port; no authentication or privilege escalation is required. If successful, the attacker can disrupt service for the targeted directory instance, potentially affecting applications that depend on the directory.

Generated by OpenCVE AI on August 2, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Oracle patch that addresses this denial‑of‑service flaw for Oracle Unified Directory
  • Restrict LDAP traffic to trusted networks or apply firewall rules to limit external access
  • Configure automatic service restarts or high availability to minimize downtime after a crash

Generated by OpenCVE AI on August 2, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Denial of Service in Oracle Unified Directory

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Denial of Service in Oracle Unified Directory

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Denial of Service in Oracle Unified Directory

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:35:08.185Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60425

cve-icon Vulnrichment

Updated: 2026-07-24T15:34:52.180Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption