Impact
The Oracle Unified Directory product contains a flaw that permits an attacker with low privileges and network access over LDAP to read or modify directory data. This weakness allows the adversary to enumerate and retrieve sensitive attributes, and in some cases to alter or delete entries. The impact is primarily confidentiality, with the possibility of altering integrity for a subset of data, as reflected in the CVSS vector.
Affected Systems
The flaw affects Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware. The issue may also extend to other Oracle products that rely on the directory service, thereby broadening the potential scope.
Risk and Exploitability
The CVSS score of 8.5 denotes a high severity, and the EPSS score of less than 1% indicates low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, implying no known live attacks. Attackers can exploit the flaw over the network via LDAP with only low privileges, potentially compromising all accessible directory data. Given these factors, the risk remains significant for organizations dependent on Oracle Unified Directory.
OpenCVE Enrichment