Impact
The vulnerability stems from an improper access control flaw that allows an unauthenticated attacker with network reachability to the LDAP service to bypass authentication checks in Oracle Unified Directory. Successful exploitation can grant the attacker the ability to read critical directory data, as well as insert, update, or delete entries, effectively providing complete control over all data accessible through the directory.
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected, as specified by Oracle and reflected in the relevant CPE entries.
Risk and Exploitability
The CVSS base score of 8.2 indicates a significant confidentiality and integrity impact. The EPSS score of less than 1% indicates a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers only need network access to the LDAP service, the attack vector being straightforward unauthenticated LDAP connections; no privileged access or user interaction is required.
OpenCVE Enrichment