Impact
A flaw in the Oracle Unified Directory OUD Core component allows an attacker with low privileges but network access via LDAP to bypass authentication controls and assume full control of the directory service. The vulnerability is exploitable over the network without any user interaction and can result in complete takeover of the Oracle Unified Directory service, affecting confidentiality, integrity, and availability, and represents an Access Control flaw (CWE-284).
Affected Systems
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, both part of Oracle Fusion Middleware, are affected. Deployments using these versions of the directory service are at risk, and attacks may also impact other Oracle products
Risk and Exploitability
The CVSS 3.1 base score of 9.9 indicates a Critical severity impact on all data and system operations. The EPSS score of less than 1% shows a low probability of exploitation at present, yet the exploit requires only network access to LDAP and a low‑privileged account, making it a realistic threat once discovered. The vulnerability is not yet listed in the CISA KEV catalog, so there are no confirmed active exploits known at the time of this analysis.
OpenCVE Enrichment