Impact
The vulnerability in Oracle Unified Directory allows an unauthenticated attacker with network access via LDAP to perform unauthorized creation, deletion, or modification of directory entries, resulting in loss of confidentiality and integrity of all data accessible through the service. The weakness is a lack of proper access control for LDAP operations, as identified by CWE-284.
Affected Systems
Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0, components of Oracle Fusion Middleware, are affected. These versions are deployed in environments exposed to LDAP traffic from internal or external networks.
Risk and Exploitability
The CVSS 8.7 indicates high impact on confidentiality and integrity. EPSS less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in KEV. Attackers require only network connectivity to the LDAP endpoint; no authentication is needed, making the attack vector simple and reachable. The flaw’s scope change may also affect other Oracle products that rely on the directory service.
OpenCVE Enrichment