Impact
A remote, unauthenticated attacker with network access to the LDAP interface of Oracle Unified Directory can trigger an easily exploitable flaw that causes the server to hang or repeatedly crash. The vulnerability does not expose data or permit remote code execution; it only impacts availability, as reflected in its CVSS base score of 7.5.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware’s OUD Core component, are affected.
Risk and Exploitability
The EPSS score indicates a very low but non‑zero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a simple LDAP request over the network to an exposed LDAP port; no authentication or privilege escalation is required. If successful, the attacker can disrupt service for the targeted directory instance, potentially affecting applications that depend on the directory.
OpenCVE Enrichment